Zone (*) DNSSEC - Informations Zone : (root)(root) 1 DS RR published DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest 4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=
• Status: Valid because published3 DNSKEY RR found Public Key with Algorithm 8, KeyTag 20326, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 8, KeyTag 20826, Flags 256
Public Key with Algorithm 8, KeyTag 47671, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner (root), Algorithm: 8, 0 Labels, original TTL: 172800 sec, Signature-expiration: 11.07.2022, 00:00:00 +, Signature-Inception: 20.06.2022, 00:00:00 +, KeyTag 20326, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 20326 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 8, KeyTag 20326, DigestType 2 and Digest "4G1EuAuPHTmpXAsNfGXQhFjogECbvGg0VxBCN8f47I0=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : czcz 1 DS RR in the parent zone found DS with Algorithm 13, KeyTag 20237, DigestType 2 and Digest z/Dz7NvFKcHwAxuhhAv7g1hTuSCe0eUI//SEUde3eOI=
1 RRSIG RR to validate DS RR found RRSIG-Owner cz., Algorithm: 8, 1 Labels, original TTL: 86400 sec, Signature-expiration: 06.07.2022, 05:00:00 +, Signature-Inception: 23.06.2022, 04:00:00 +, KeyTag 47671, Signer-Name: (root)
• Status: Good - Algorithmus 8 and DNSKEY with KeyTag 47671 used to validate the DS RRSet in the parent zone2 DNSKEY RR found Public Key with Algorithm 13, KeyTag 20237, Flags 257 (SEP = Secure Entry Point)
Public Key with Algorithm 13, KeyTag 60306, Flags 256
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner cz., Algorithm: 13, 1 Labels, original TTL: 3600 sec, Signature-expiration: 04.07.2022, 06:21:34 +, Signature-Inception: 20.06.2022, 04:51:34 +, KeyTag 20237, Signer-Name: cz
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 20237 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 20237, DigestType 2 and Digest "z/Dz7NvFKcHwAxuhhAv7g1hTuSCe0eUI//SEUde3eOI=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : cuni.czcuni.cz 1 DS RR in the parent zone found DS with Algorithm 13, KeyTag 32757, DigestType 2 and Digest UM30TtMbFHOYe0dZ24fn+oZmR/9Bvy1GjrKkv3tCdgw=
1 RRSIG RR to validate DS RR found RRSIG-Owner cuni.cz., Algorithm: 13, 2 Labels, original TTL: 3600 sec, Signature-expiration: 04.07.2022, 03:50:45 +, Signature-Inception: 20.06.2022, 02:20:45 +, KeyTag 60306, Signer-Name: cz
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 60306 used to validate the DS RRSet in the parent zone1 DNSKEY RR found Public Key with Algorithm 13, KeyTag 32757, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner cuni.cz., Algorithm: 13, 2 Labels, original TTL: 86400 sec, Signature-expiration: 01.07.2022, 11:59:11 +, Signature-Inception: 01.06.2022, 11:55:41 +, KeyTag 32757, Signer-Name: cuni.cz
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 32757 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 32757, DigestType 2 and Digest "UM30TtMbFHOYe0dZ24fn+oZmR/9Bvy1GjrKkv3tCdgw=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : mff.cuni.czmff.cuni.cz 1 DS RR in the parent zone found DS with Algorithm 13, KeyTag 47500, DigestType 2 and Digest blMWqSvxrJX0+ZFvVxldMFqeCO99D92mJ09HsDpqvBk=
1 RRSIG RR to validate DS RR found RRSIG-Owner mff.cuni.cz., Algorithm: 13, 3 Labels, original TTL: 86400 sec, Signature-expiration: 19.07.2022, 11:52:43 +, Signature-Inception: 19.06.2022, 10:54:52 +, KeyTag 32757, Signer-Name: cuni.cz
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 32757 used to validate the DS RRSet in the parent zone1 DNSKEY RR found Public Key with Algorithm 13, KeyTag 47500, Flags 257 (SEP = Secure Entry Point)
1 RRSIG RR to validate DNSKEY RR found RRSIG-Owner mff.cuni.cz., Algorithm: 13, 3 Labels, original TTL: 28800 sec, Signature-expiration: 29.08.2022, 03:13:00 +, Signature-Inception: 01.05.2022, 03:03:13 +, KeyTag 47500, Signer-Name: mff.cuni.cz
• Status: Good - Algorithmus 13 and DNSKEY with KeyTag 47500 used to validate the DNSKEY RRSet• Status: Valid Chain of trust. Parent-DS with Algorithm 13, KeyTag 47500, DigestType 2 and Digest "blMWqSvxrJX0+ZFvVxldMFqeCO99D92mJ09HsDpqvBk=" validates local Key with the same values, Key ist Secure Entry Point (SEP) of the zoneZone : troja.mff.cuni.cztroja.mff.cuni.cz 0 DS RR in the parent zone found DS-Query in the parent zone has a valid NSEC3 RR as result with the hashed query name "eqo84l6i475g1qteb3hu82up4btond47" between the hashed NSEC3-owner "eqo84l6i475g1qteb3hu82up4btond47" and the hashed NextOwner "er9j2mnvd54baeui4gglh04ihi31h3lf". So the parent zone confirmes the not-existence of a DS RR.Bitmap: No Bitmap? Validated: RRSIG-Owner eqo84l6i475g1qteb3hu82up4btond47.mff.cuni.cz., Algorithm: 13, 4 Labels, original TTL: 3600 sec, Signature-expiration: 10.09.2022, 20:08:14 +, Signature-Inception: 13.05.2022, 19:31:23 +, KeyTag 47500, Signer-Name: mff.cuni.cz
0 DNSKEY RR found Zone : utef70-dynip.troja.mff.cuni.czutef70-dynip.troja.mff.cuni.cz 0 DS RR in the parent zone found Zone : www.utef70-dynip.troja.mff.cuni.czwww.utef70-dynip.troja.mff.cuni.cz 0 DS RR in the parent zone found