Zone (*) DNSSEC - Informations (beta) Zone : (root)(root) 1 DS RR published • Status: Valid because published2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point) Public Key with Algorithm 8, KeyTag 22545, Flags 256 1 RRSIG RR to validate DNSKEY RR found • Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 31.12.2019, 00:00:00, Signature-Inception: 10.12.2019, 00:00:00, KeyTag 20326, Signer-Name: (root)• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : auau 4 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 23.12.2019, 17:00:00, Signature-Inception: 10.12.2019, 16:00:00, KeyTag 22545, Signer-Name: (root) • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 22545 used to validate the DS RRSet in the parent zone3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 18875, Flags 257 (SEP = Secure Entry Point) Public Key with Algorithm 8, KeyTag 20647, Flags 257 (SEP = Secure Entry Point) Public Key with Algorithm 8, KeyTag 49951, Flags 256 3 RRSIG RR to validate DNSKEY RR found • Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 08.03.2020, 19:25:38, Signature-Inception: 09.12.2019, 19:09:50, KeyTag 18875, Signer-Name: au• Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 08.03.2020, 19:25:38, Signature-Inception: 09.12.2019, 19:09:50, KeyTag 20647, Signer-Name: au• Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 08.03.2020, 19:25:38, Signature-Inception: 09.12.2019, 19:09:50, KeyTag 49951, Signer-Name: au• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 18875 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20647 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 49951 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 18875, DigestType 1 and Digest "pjYtk4QpR3wPXlHh9Ho1FrOdKBs=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 18875, DigestType 2 and Digest "/nc7L3e7am3TG6J+sZ6PZCV5N2Isq5jzkm7nf+or558=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20647, DigestType 1 and Digest "ocLzYCzRcc8/vNolUjwIaGfSnMY=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20647, DigestType 2 and Digest "78eXX8of7Std82JKfvq17SCvQtyD9dnsHTtMmQuOK1Q=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : com.aucom.au 2 DS RR in the parent zone found 1 RRSIG RR to validate DS RR found Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 09.03.2020, 13:32:48, Signature-Inception: 10.12.2019, 13:32:05, KeyTag 49951, Signer-Name: au • Status: Good - Algorithmus 8 and DNSKEY with KeyTag 49951 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 8, KeyTag 14185, Flags 257 (SEP = Secure Entry Point) Public Key with Algorithm 8, KeyTag 14968, Flags 256 2 RRSIG RR to validate DNSKEY RR found • Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 30.12.2019, 15:17:44, Signature-Inception: 09.12.2019, 14:17:44, KeyTag 14185, Signer-Name: com.au• Algorithm: 8, 2 Labels, original TTL: 86400 sec, Signature-expiration: 30.12.2019, 15:17:44, Signature-Inception: 09.12.2019, 14:17:44, KeyTag 14968, Signer-Name: com.au• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14185 used to validate the DNSKEY RRSet• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 14968 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 14185, DigestType 1 and Digest "LwMkLkF6mgH36ROfYFtIzDii1FQ=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zone• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 14185, DigestType 2 and Digest "k5S+oJ9evZE4SqXNA5ems5X9KymceRKXkkPNaJujh9s=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : avsion.com.auavsion.com.au 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed domain name between the hashed NSEC3-owner and the hashed NextOwner. So the parent zone confirmes the non-existence of a DS RR. 0 DNSKEY RR found Zone : unifi.avsion.com.auunifi.avsion.com.au 0 DS RR in the parent zone found 0 DNSKEY RR found Zone : www.unifi.avsion.com.auwww.unifi.avsion.com.au 0 DS RR in the parent zone found