Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published • Status: Valid because published3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 33853, Flags 256
Public Key with Algorithm 8, KeyTag 48903, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.04.2020, 00:00:00 +, Signature-Inception: 21.03.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : meme 2 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found RRSIG-Owner me., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 07.04.2020, 05:00:00 +, Signature-Inception: 25.03.2020, 04:00:00 +, KeyTag 33853, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33853 used to validate the DS RRSet in the parent zone4 DNSKEY RR found Public Key with Algorithm 7, KeyTag 2569, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 7, KeyTag 46829, Flags 256
Public Key with Algorithm 7, KeyTag 53233, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 7, KeyTag 55358, Flags 256
3 RRSIG RR to validate DNSKEY RR found RRSIG-Owner me., Algorithm: 7, 1 Labels, original TTL: 900 sec, Signature-expiration: 07.04.2020, 15:18:20 +, Signature-Inception: 17.03.2020, 14:18:20 +, KeyTag 2569, Signer-Name: me
RRSIG-Owner me., Algorithm: 7, 1 Labels, original TTL: 900 sec, Signature-expiration: 07.04.2020, 15:18:20 +, Signature-Inception: 17.03.2020, 14:18:20 +, KeyTag 46829, Signer-Name: me
RRSIG-Owner me., Algorithm: 7, 1 Labels, original TTL: 900 sec, Signature-expiration: 07.04.2020, 15:18:20 +, Signature-Inception: 17.03.2020, 14:18:20 +, KeyTag 53233, Signer-Name: me
• Status: Good - Algorithmus 7 and DNSKEY with KeyTag 2569 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 7 and DNSKEY with KeyTag 46829 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 7 and DNSKEY with KeyTag 53233 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 2569, DigestType 1 and Digest "CboetNIEAmIIgf2YSJlEF4ANsmo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone• Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 2569, DigestType 2 and Digest "lOeYEG8DNQDmdWexl66RMsDpFnZNx0PFWp7KPHv1WeI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : nctu.menctu.me 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "f5orq72af3kcc66gtcs27736i8j2kqfb" between the hashed NSEC3-owner "f5me8en6pk96rl45l95l2dkqkpanlqpg" and the hashed NextOwner "f5tu4248ds8iougrtd2597v6g36i0a8v". So the parent zone confirmes the not-existence of a DS RR.Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner f5me8en6pk96rl45l95l2dkqkpanlqpg.me., Algorithm: 7, 2 Labels, original TTL: 8400 sec, Signature-expiration: 07.04.2020, 15:18:20 +, Signature-Inception: 17.03.2020, 14:18:20 +, KeyTag 46829, Signer-Name: me
0 DNSKEY RR found Zone : ts4docker.nctu.mets4docker.nctu.me 0 DS RR in the parent zone found 0 DNSKEY RR found Zone : www.ts4docker.nctu.mewww.ts4docker.nctu.me 0 DS RR in the parent zone found