Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 22545, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 31.12.2019, 00:00:00 +, Signature-Inception: 10.12.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: one
|
|
one
| 2 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner one., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.12.2019, 05:00:00 +, Signature-Inception: 11.12.2019, 04:00:00 +, KeyTag 22545, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22545 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 7024, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 18606, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 33631, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 3 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner one., Algorithm: 8, 1 Labels, original TTL: 900 sec, Signature-expiration: 05.01.2020, 22:31:40 +, Signature-Inception: 06.12.2019, 22:10:50 +, KeyTag 7024, Signer-Name: one
|
|
|
|
|
| RRSIG-Owner one., Algorithm: 8, 1 Labels, original TTL: 900 sec, Signature-expiration: 05.01.2020, 22:31:40 +, Signature-Inception: 06.12.2019, 22:10:50 +, KeyTag 18606, Signer-Name: one
|
|
|
|
|
| RRSIG-Owner one., Algorithm: 8, 1 Labels, original TTL: 900 sec, Signature-expiration: 05.01.2020, 22:31:40 +, Signature-Inception: 06.12.2019, 22:10:50 +, KeyTag 33631, Signer-Name: one
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 7024 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 18606 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 33631 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 7024, DigestType 1 and Digest "R02Xr0yAokX2uMRqiEs02K+3ORo=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 7024, DigestType 2 and Digest "MeFT4ZjN5OIGqVH1dkWMgWAhCD2wqyFRW4FYs6BdsfY=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: ryde.one
|
|
ryde.one
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "39iopl061oomb4jqbck9o76re99vflek" between the hashed NSEC3-owner "39iob9dl5725n2vrmjeit6rrbk9fe0v5" and the hashed NextOwner "39n2e9fm0akb36a9e23feoit71nli1ok". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner 39iob9dl5725n2vrmjeit6rrbk9fe0v5.one., Algorithm: 8, 2 Labels, original TTL: 1800 sec, Signature-expiration: 09.01.2020, 20:01:28 +, Signature-Inception: 10.12.2019, 19:48:16 +, KeyTag 18606, Signer-Name: one
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: git.ryde.one
|
|
git.ryde.one
| 0 DS RR in the parent zone found
|
|
|
Zone: www.git.ryde.one
|
|
www.git.ryde.one
| 0 DS RR in the parent zone found
|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 22545, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 31.12.2019, 00:00:00 +, Signature-Inception: 10.12.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: com
|
|
com
| 1 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.12.2019, 05:00:00 +, Signature-Inception: 11.12.2019, 04:00:00 +, KeyTag 22545, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22545 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 12163, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 17708, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 30909, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.12.2019, 19:24:21 +, Signature-Inception: 07.12.2019, 19:19:21 +, KeyTag 30909, Signer-Name: com
|
|
|
|
|
| RRSIG-Owner com., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 22.12.2019, 19:24:21 +, Signature-Inception: 07.12.2019, 19:19:21 +, KeyTag 30909, Signer-Name: com
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30909 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 30909, DigestType 2 and Digest "4tPJFvbe6scylOgmj7WIUESoM/xUWViPSpGEz8QaV2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: amazonaws.com
|
|
amazonaws.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "f1rgvh3kf6di3tf72pim4t6uom70c5h4" between the hashed NSEC3-owner "f1rgna383qhejvt6vn8tmlodbhca40fl" and the hashed NextOwner "f1rhm5niqh2q22thlcsi43iumu15l4us". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: NS, DS, RRSIG Validated: RRSIG-Owner f1rgna383qhejvt6vn8tmlodbhca40fl.com., Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 17.12.2019, 07:14:48 +, Signature-Inception: 10.12.2019, 06:04:48 +, KeyTag 12163, Signer-Name: com
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: compute.amazonaws.com
|
|
compute.amazonaws.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: eu-west-1.compute.amazonaws.com
|
|
eu-west-1.compute.amazonaws.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
Zone: ec2-18-202-33-37.eu-west-1.compute.amazonaws.com
|
|
ec2-18-202-33-37.eu-west-1.compute.amazonaws.com
| 0 DS RR in the parent zone found
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|