Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published • Status: Valid because published3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 16749, Flags 256
Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 25266, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 22.04.2019, 00:00:00 +, Signature-Inception: 01.04.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : brbr 1 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found RRSIG-Owner br., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 15.04.2019, 17:00:00 +, Signature-Inception: 02.04.2019, 16:00:00 +, KeyTag 25266, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 25266 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 13, KeyTag 2471, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 36119, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner br., Algorithm: 13, 1 Labels, original TTL: 21600 sec, Signature-expiration: 21.04.2019, 12:00:00 +, Signature-Inception: 31.03.2019, 12:00:00 +, KeyTag 2471, Signer-Name: br
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 2471 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 2471, DigestType 2 and Digest "Xk81mYuPkJVX+hGcTL/cotZgom8GnvAGtAN1igfRouQ=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : com.brcom.br 1 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found RRSIG-Owner com.br., Algorithm: 13, 2 Labels, original TTL: 21600 sec, Signature-expiration: 16.04.2019, 12:00:10 +, Signature-Inception: 02.04.2019, 11:00:10 +, KeyTag 36119, Signer-Name: br
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 36119 used to validate the DS RRSet in the parent zone1 DNSKEY RR found Public Key with Algorithm 13, KeyTag 47162, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner com.br., Algorithm: 13, 2 Labels, original TTL: 21600 sec, Signature-expiration: 17.04.2019, 00:30:08 +, Signature-Inception: 02.04.2019, 23:30:08 +, KeyTag 47162, Signer-Name: com.br
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 47162 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 47162, DigestType 2 and Digest "hiPCFTAQ8ksJAKyaSg5kbEanLDYDJFU7pQFNYEDTOGg=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : baxai.com.brbaxai.com.br 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "sl27jhaiqtgqt0himltts7p0i2o88gls" between the hashed NSEC3-owner "sl27iq6rv1cab06o0mj0s6p8l80dvjqf" and the hashed NextOwner "sl2cbprc9l18mkghvk2ub51jukfvr59u". So the parent zone confirmes the not-existence of a DS RR.Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner sl27iq6rv1cab06o0mj0s6p8l80dvjqf.com.br., Algorithm: 13, 3 Labels, original TTL: 900 sec, Signature-expiration: 14.04.2019, 09:30:07 +, Signature-Inception: 31.03.2019, 08:30:07 +, KeyTag 47162, Signer-Name: com.br
0 DNSKEY RR found Zone : www.baxai.com.brwww.baxai.com.br 0 DS RR in the parent zone found