Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 59944, Flags 256
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 30.09.2019, 00:00:00 +, Signature-Inception: 09.09.2019, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: cz
|
|
cz
| 1 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner cz., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 26.09.2019, 05:00:00 +, Signature-Inception: 13.09.2019, 04:00:00 +, KeyTag 59944, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 59944 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 1524, Flags 256
|
|
|
|
|
| Public Key with Algorithm 13, KeyTag 20237, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner cz., Algorithm: 13, 1 Labels, original TTL: 18000 sec, Signature-expiration: 27.09.2019, 01:47:43 +, Signature-Inception: 13.09.2019, 11:35:38 +, KeyTag 1524, Signer-Name: cz
|
|
|
|
|
| RRSIG-Owner cz., Algorithm: 13, 1 Labels, original TTL: 18000 sec, Signature-expiration: 25.09.2019, 00:00:00 +, Signature-Inception: 11.09.2019, 00:00:00 +, KeyTag 20237, Signer-Name: cz
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 1524 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 20237 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 20237, DigestType 2 and Digest "z/Dz7NvFKcHwAxuhhAv7g1hTuSCe0eUI//SEUde3eOI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: muni.cz
|
|
muni.cz
| 1 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner muni.cz., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 22.09.2019, 23:46:46 +, Signature-Inception: 10.09.2019, 23:35:31 +, KeyTag 1524, Signer-Name: cz
|
|
|
|
|
| • Status: Good - Algorithmus 13 and DNSKEY with KeyTag 1524 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 26957, Flags 256
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 41133, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner muni.cz., Algorithm: 7, 2 Labels, original TTL: 7200 sec, Signature-expiration: 30.11.2019, 00:00:00 +, Signature-Inception: 12.09.2019, 10:37:06 +, KeyTag 26957, Signer-Name: muni.cz
|
|
|
|
|
| RRSIG-Owner muni.cz., Algorithm: 7, 2 Labels, original TTL: 7200 sec, Signature-expiration: 30.11.2019, 00:00:00 +, Signature-Inception: 12.09.2019, 10:37:06 +, KeyTag 41133, Signer-Name: muni.cz
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 26957 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 41133 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 41133, DigestType 2 and Digest "Ze0w6H5olbIMl9clEaR4GsJh/kBqFrvPFK2MzY8RKZg=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: ics.muni.cz
|
|
ics.muni.cz
| 2 DS RR in the parent zone found
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner ics.muni.cz., Algorithm: 7, 3 Labels, original TTL: 7200 sec, Signature-expiration: 30.11.2019, 00:00:00 +, Signature-Inception: 12.09.2019, 10:37:06 +, KeyTag 26957, Signer-Name: muni.cz
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 26957 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 43649, Flags 256
|
|
|
|
|
| Public Key with Algorithm 7, KeyTag 47829, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner ics.muni.cz., Algorithm: 7, 3 Labels, original TTL: 7200 sec, Signature-expiration: 31.10.2019, 00:00:00 +, Signature-Inception: 06.09.2019, 07:27:35 +, KeyTag 43649, Signer-Name: ics.muni.cz
|
|
|
|
|
| RRSIG-Owner ics.muni.cz., Algorithm: 7, 3 Labels, original TTL: 7200 sec, Signature-expiration: 31.10.2019, 00:00:00 +, Signature-Inception: 06.09.2019, 07:27:35 +, KeyTag 47829, Signer-Name: ics.muni.cz
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 43649 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 7 and DNSKEY with KeyTag 47829 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 47829, DigestType 1 and Digest "KL+5zoaCd5eq9eOlJrLJBsGSN2Y=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 7, KeyTag 47829, DigestType 2 and Digest "EGeFNCkDP3wyn2D97u8bSBDtct8arUZYRkJjMDKvcN8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: icinga-demo.ics.muni.cz
|
|
icinga-demo.ics.muni.cz
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "7hdr0ta329nq0l1npflqdli71nqicvo7" between the hashed NSEC3-owner "7hdr0ta329nq0l1npflqdli71nqicvo7" and the hashed NextOwner "7hiv44cuusrpv77n06uvgk77s0jhpurj". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner 7hdr0ta329nq0l1npflqdli71nqicvo7.ics.muni.cz., Algorithm: 7, 4 Labels, original TTL: 7200 sec, Signature-expiration: 31.10.2019, 00:00:00 +, Signature-Inception: 06.09.2019, 07:27:35 +, KeyTag 43649, Signer-Name: ics.muni.cz
|
|
|
Zone: www.icinga-demo.ics.muni.cz
|
|
www.icinga-demo.ics.muni.cz
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "lnhpbn3de7jqnvt99g86vpajgh33mfa1" between the hashed NSEC3-owner "lm77o1dd2m6qla7oj7t0fseup1hqnioh" and the hashed NextOwner "lnmu0vjt4mr9amvofh35r2d50krfj8ks". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, RRSIG Validated: RRSIG-Owner lm77o1dd2m6qla7oj7t0fseup1hqnioh.ics.muni.cz., Algorithm: 7, 4 Labels, original TTL: 7200 sec, Signature-expiration: 31.10.2019, 00:00:00 +, Signature-Inception: 06.09.2019, 07:27:35 +, KeyTag 43649, Signer-Name: ics.muni.cz
|