Zone (*) | DNSSEC - Informations |
---|
|
|
Zone: (root)
|
|
(root)
| 1 DS RR published
|
|
|
|
|
| DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
|
|
|
|
|
| • Status: Valid because published
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 5613, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 1 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 02.05.2024, 00:00:00 +, Signature-Inception: 11.04.2024, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: ar
|
|
ar
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 19606, DigestType 2 and Digest RBXPGizxDelLkrwCDyHRv0FjsukPKm9qXSoXQDOdVmw=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner ar., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 24.04.2024, 05:00:00 +, Signature-Inception: 11.04.2024, 04:00:00 +, KeyTag 5613, Signer-Name: (root)
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 5613 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 2 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 14574, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 19606, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner ar., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 02.05.2024, 13:49:05 +, Signature-Inception: 03.04.2024, 12:04:16 +, KeyTag 14574, Signer-Name: ar
|
|
|
|
|
| RRSIG-Owner ar., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 15.08.2024, 11:22:33 +, Signature-Inception: 23.01.2024, 12:34:56 +, KeyTag 19606, Signer-Name: ar
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14574 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 19606 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 19606, DigestType 2 and Digest "RBXPGizxDelLkrwCDyHRv0FjsukPKm9qXSoXQDOdVmw=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: edu.ar
|
|
edu.ar
| 1 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 18482, DigestType 1 and Digest T8aGvbyU4qUgCpIF+Da43lCus5A=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner edu.ar., Algorithm: 8, 2 Labels, original TTL: 7200 sec, Signature-expiration: 05.05.2024, 14:11:12 +, Signature-Inception: 06.04.2024, 06:03:54 +, KeyTag 14574, Signer-Name: ar
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14574 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 4 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 16096, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 18482, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 30010, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 36370, Flags 256
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner edu.ar., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 15.04.2024, 00:54:42 +, Signature-Inception: 15.03.2024, 11:46:29 +, KeyTag 16096, Signer-Name: edu.ar
|
|
|
|
|
| RRSIG-Owner edu.ar., Algorithm: 8, 2 Labels, original TTL: 3600 sec, Signature-expiration: 15.04.2024, 00:54:42 +, Signature-Inception: 15.03.2024, 11:46:29 +, KeyTag 18482, Signer-Name: edu.ar
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 16096 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 18482 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 18482, DigestType 1 and Digest "T8aGvbyU4qUgCpIF+Da43lCus5A=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: riu.edu.ar
|
|
riu.edu.ar
| 4 DS RR in the parent zone found
|
|
|
|
|
| DS with Algorithm 8, KeyTag 40562, DigestType 1 and Digest CPqDVqUV4uLfi9h0nbpqyOLzEb8=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 40562, DigestType 2 and Digest giY8b0QRW3Dv0dbTUGDLw5GsCvRXSthqossrZK6DdXE=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 56846, DigestType 1 and Digest Xe1K3XbLxe9E90SlFkAEQ1lEV+8=
|
|
|
|
|
| DS with Algorithm 8, KeyTag 56846, DigestType 2 and Digest Uvjl3aB6xBfCANM6tsrEbBskPiSiDJD8MKz6C1KDMNg=
|
|
|
|
|
| 1 RRSIG RR to validate DS RR found
|
|
|
|
|
| RRSIG-Owner riu.edu.ar., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 10.05.2024, 22:47:15 +, Signature-Inception: 10.04.2024, 03:00:01 +, KeyTag 30010, Signer-Name: edu.ar
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 30010 used to validate the DS RRSet in the parent zone
|
|
|
|
|
| 3 DNSKEY RR found
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 12669, Flags 256
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 40562, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| Public Key with Algorithm 8, KeyTag 56846, Flags 257 (SEP = Secure Entry Point)
|
|
|
|
|
| 2 RRSIG RR to validate DNSKEY RR found
|
|
|
|
|
| RRSIG-Owner riu.edu.ar., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 25.04.2024, 05:56:53 +, Signature-Inception: 24.03.2024, 18:47:00 +, KeyTag 40562, Signer-Name: riu.edu.ar
|
|
|
|
|
| RRSIG-Owner riu.edu.ar., Algorithm: 8, 3 Labels, original TTL: 3600 sec, Signature-expiration: 25.04.2024, 05:56:53 +, Signature-Inception: 24.03.2024, 18:47:00 +, KeyTag 56846, Signer-Name: riu.edu.ar
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 40562 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 56846 used to validate the DNSKEY RRSet
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 40562, DigestType 1 and Digest "CPqDVqUV4uLfi9h0nbpqyOLzEb8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 40562, DigestType 2 and Digest "giY8b0QRW3Dv0dbTUGDLw5GsCvRXSthqossrZK6DdXE=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 56846, DigestType 1 and Digest "Xe1K3XbLxe9E90SlFkAEQ1lEV+8=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
|
|
| • Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 56846, DigestType 2 and Digest "Uvjl3aB6xBfCANM6tsrEbBskPiSiDJD8MKz6C1KDMNg=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone
|
|
|
Zone: misp.riu.edu.ar
|
|
misp.riu.edu.ar
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" between the hashed NSEC3-owner "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" and the hashed NextOwner "8rg1vslfbl6tfb63dddbbt3bssdl0v30". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| 0 DNSKEY RR found
|
|
|
|
|
|
|
|
|
|
|
| RRSIG Type 1 validates the A - Result: 170.210.5.23
Validated: RRSIG-Owner misp.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 1800 sec, Signature-expiration: 23.04.2024, 04:32:36 +, Signature-Inception: 23.03.2024, 15:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| RRSIG Type 28 validates the AAAA - Result: 2800:0110:0005:0000:0000:0000:0000:0023
Validated: RRSIG-Owner misp.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 1800 sec, Signature-expiration: 24.04.2024, 00:50:25 +, Signature-Inception: 24.03.2024, 11:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| CNAME-Query sends a valid NSEC3 RR as result with the hashed query name "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" equal the hashed NSEC3-owner "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" and the hashed NextOwner "8rg1vslfbl6tfb63dddbbt3bssdl0v30". So the zone confirmes the not-existence of that CNAME RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TXT-Query sends a valid NSEC3 RR as result with the hashed query name "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" equal the hashed NSEC3-owner "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" and the hashed NextOwner "8rg1vslfbl6tfb63dddbbt3bssdl0v30". So the zone confirmes the not-existence of that TXT RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
|
|
| TLSA-Query (_443._tcp.misp.riu.edu.ar) sends a valid NSEC3 RR as result with the hashed owner name "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" (unhashed: misp.riu.edu.ar). So that's the Closest Encloser of the query name.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Next Closer Name "fccee90edke50pbn7tm3h2onbr8am6s6" (unhashed: _tcp.misp.riu.edu.ar) with the owner "fbn061fsntcddj9aiqg9gluehruuj0r8" and the NextOwner "fdqm2m9198osb4glm94evguo9vuts89v". So that NSEC3 confirms the not-existence of the Next Closer Name.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner fbn061fsntcddj9aiqg9gluehruuj0r8.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 18:09:17 +, Signature-Inception: 09.04.2024, 01:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| TLSA-Query sends a valid NSEC3 RR as result and covers the hashed Wildcard expansion of the ClosestEncloser "qi3mh6r4netcfcg95bq657gp3mkke8b0" (unhashed: *.misp.riu.edu.ar) with the owner "qf6o01hu4793k6032hoc1s75l0hq3jum" and the NextOwner "qj42jougdd4vlkit92c9bdcpls55fsva". So that NSEC3 confirms the not-existence of the Wildcard expansion.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner qf6o01hu4793k6032hoc1s75l0hq3jum.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 10.05.2024, 00:39:42 +, Signature-Inception: 08.04.2024, 23:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NXDomain-Proof required and found.
|
|
|
|
|
| CAA-Query sends a valid NSEC3 RR as result with the hashed query name "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" equal the hashed NSEC3-owner "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" and the hashed NextOwner "8rg1vslfbl6tfb63dddbbt3bssdl0v30". So the zone confirmes the not-existence of that CAA RR, but the existence of that query name (minimal one RR with that name exists).
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| Status: Good. NoData-Proof required and found.
|
|
|
Zone: www.misp.riu.edu.ar
|
|
www.misp.riu.edu.ar
| 0 DS RR in the parent zone found
|
|
|
|
|
| DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "56t1tfunsltbi7qao19ho6rtr1bh2vm6" between the hashed NSEC3-owner "5609f5basc1tl5etq7bhns0pd6iuuj3l" and the hashed NextOwner "577redhhbccmb4n1pova4hs1euj54elu". So the parent zone confirmes the not-existence of a DS RR.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 5609f5basc1tl5etq7bhns0pd6iuuj3l.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 23:11:28 +, Signature-Inception: 08.04.2024, 13:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| DS-Query in the parent zone sends valid NSEC3 RR with the Hash "8qn1pkgc9k0bg7lol2p5nel3j34l7i5q" as Owner. That's the Hash of "misp.riu.edu.ar" with the NextHashedOwnerName "8rg1vslfbl6tfb63dddbbt3bssdl0v30". So that domain name is the Closest Encloser of "www.misp.riu.edu.ar". Opt-Out: False.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner 8qn1pkgc9k0bg7lol2p5nel3j34l7i5q.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 09.05.2024, 10:47:02 +, Signature-Inception: 08.04.2024, 07:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|
|
|
|
|
| The ClosestEncloser says, that "*.misp.riu.edu.ar" with the Hash "qi3mh6r4netcfcg95bq657gp3mkke8b0" is a possible Wildcard of the DS Query Name. But the DS-Query in the parent zone sends a valid NSEC3 RR With the owner "qf6o01hu4793k6032hoc1s75l0hq3jum" and the Next Owner "qj42jougdd4vlkit92c9bdcpls55fsva", so the Hash of the wildcard is between these hashes. So that NSEC3 proves the Not-existence of that wildcard expansion. Opt-Out: False.
Bitmap: A, AAAA, RRSIG Validated: RRSIG-Owner qf6o01hu4793k6032hoc1s75l0hq3jum.riu.edu.ar., Algorithm: 8, 4 Labels, original TTL: 3600 sec, Signature-expiration: 10.05.2024, 00:39:42 +, Signature-Inception: 08.04.2024, 23:00:01 +, KeyTag 12669, Signer-Name: riu.edu.ar
|