Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 33853, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.04.2020, 00:00:00 +, Signature-Inception: 11.03.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: gov
|
|
gov
| 2 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner gov., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2020, 05:00:00 +, Signature-Inception: 14.03.2020, 04:00:00 +, KeyTag 33853, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33853 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 7698, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 36558, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner gov., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 25.03.2020, 19:02:54 +, Signature-Inception: 10.03.2020, 18:57:54 +, KeyTag 7698, Signer-Name: gov
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 7698 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 7698, DigestType 1 and Digest "bxCbRqgM6pYT3IbVo+BlUgUFqv4=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 7698, DigestType 2 and Digest "a8lJ5jhELq0L2vCTV2PI0AN2A4T/Feu9XOhrtVWVYfA=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: nih.gov
|
|
nih.gov
| 4 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner nih.gov., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 21.03.2020, 10:10:07 +, Signature-Inception: 14.03.2020, 10:10:07 +, KeyTag 36558, Signer-Name: gov
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 36558 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 35355, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 43208, Flags 256
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 44025, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 3 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner nih.gov., Algorithm: 7, 2 Labels, original TTL: 172800 sec, Signature-expiration: 18.03.2020, 15:14:53 +, Signature-Inception: 14.03.2020, 14:25:42 +, KeyTag 35355, Signer-Name: nih.gov
|
|
|
|
|
| RRSIG-Owner nih.gov., Algorithm: 7, 2 Labels, original TTL: 172800 sec, Signature-expiration: 18.03.2020, 15:14:53 +, Signature-Inception: 14.03.2020, 14:25:42 +, KeyTag 43208, Signer-Name: nih.gov
|
|
|
|
|
| RRSIG-Owner nih.gov., Algorithm: 7, 2 Labels, original TTL: 172800 sec, Signature-expiration: 18.03.2020, 15:14:53 +, Signature-Inception: 14.03.2020, 14:25:42 +, KeyTag 44025, Signer-Name: nih.gov
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 35355 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 43208 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 44025 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 35355, DigestType 1 and Digest "69MSKNOxUDHWwIWbCA7XjPkEzI0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 35355, DigestType 2 and Digest "PR/ydV+6zIlYwp/qenF1CEjMJZzNT7OSqhyjcnUcnCU=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 44025, DigestType 1 and Digest "vmnZm0s4IAWZvMBh4frSh3kBdmw=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 44025, DigestType 2 and Digest "zR1tkwYPWvBWvF+EJELixDqPPdFrjurvNM/J7LhHB4Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: cit.nih.gov
|
|
cit.nih.gov
| 4 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner cit.nih.gov., Algorithm: 7, 3 Labels, original TTL: 7200 sec, Signature-expiration: 18.03.2020, 01:04:22 +, Signature-Inception: 14.03.2020, 00:25:50 +, KeyTag 43208, Signer-Name: nih.gov
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 43208 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 19779, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 58985, Flags 256
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner cit.nih.gov., Algorithm: 7, 3 Labels, original TTL: 172800 sec, Signature-expiration: 17.03.2020, 17:52:03 +, Signature-Inception: 13.03.2020, 17:05:59 +, KeyTag 19779, Signer-Name: cit.nih.gov
|
|
|
|
|
| RRSIG-Owner cit.nih.gov., Algorithm: 7, 3 Labels, original TTL: 172800 sec, Signature-expiration: 17.03.2020, 17:52:03 +, Signature-Inception: 13.03.2020, 17:05:59 +, KeyTag 58985, Signer-Name: cit.nih.gov
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 19779 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 58985 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 19779, DigestType 1 and Digest "sde0FZbD/AfhfXQty7UK1ZnbwnU=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 19779, DigestType 2 and Digest "rDeIvBrdZ0I01XrmGwRtGhm4z2A1RitdvEOrNQVvDvE=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: cloud.cit.nih.gov
|
|
cloud.cit.nih.gov
| 0 DS RR in the parent zone found
|
|
|
Zone: www.cloud.cit.nih.gov
|
|
www.cloud.cit.nih.gov
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "vfj3emnd9nkgm6r3efahu2pdq0i6fvkv" between the hashed NSEC3-owner "vf5kvcujrmsf36vv5m3mfi65n1rodvl2" and the hashed NextOwner "vfknqo8edeabvffp7v5vuagqp906mvka". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner vf5kvcujrmsf36vv5m3mfi65n1rodvl2.cit.nih.gov., Algorithm: 7, 4 Labels, original TTL: 900 sec, Signature-expiration: 18.03.2020, 10:36:01 +, Signature-Inception: 14.03.2020, 10:22:35 +, KeyTag 58985, Signer-Name: cit.nih.gov
|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 33853, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 01.04.2020, 00:00:00 +, Signature-Inception: 11.03.2020, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: io
|
|
io
| 2 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner io., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 27.03.2020, 05:00:00 +, Signature-Inception: 14.03.2020, 04:00:00 +, KeyTag 33853, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33853 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 303, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 32376, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 57355, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner io., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 30.03.2020, 15:16:09 +, Signature-Inception: 09.03.2020, 14:16:09 +, KeyTag 303, Signer-Name: io
|
|
|
|
|
| RRSIG-Owner io., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 30.03.2020, 15:16:09 +, Signature-Inception: 09.03.2020, 14:16:09 +, KeyTag 57355, Signer-Name: io
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 303 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 57355 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 57355, DigestType 1 and Digest "Q06R4gYTT1s7CsYDsm9eApNGq8k=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 57355, DigestType 2 and Digest "laV8O6t4SdvN33xyracaiBRrFBEQMYylvmcgV+hlw+I=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: github.io
|
|
github.io
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "ldmu4lbv0s4sttf4js642ig931pa6gjs" between the hashed NSEC3-owner "ldl8iscjau4ngcq5m160b1gbj7je9bj1" and the hashed NextOwner "ldnao8focvluj5m8p8mr3aflkg8rnd2s". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner ldl8iscjau4ngcq5m160b1gbj7je9bj1.io., Algorithm: 8, 2 Labels, original TTL: 900 sec, Signature-expiration: 30.03.2020, 15:16:09 +, Signature-Inception: 09.03.2020, 14:16:09 +, KeyTag 303, Signer-Name: io
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: nihgov.github.io
|
|
nihgov.github.io
| 0 DS RR in the parent zone found
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|