[ldns-users] bug in drill?

Gilles Massen gilles.massen at restena.lu
Wed Mar 16 10:01:00 UTC 2011


When running a drill on ns1.dns.lu (or any other existing name in
dns.lu), I get an error, but still a correct result. It looks like a
bug, but so far I have been unable to tie it to something specific,
although I would suspect that it is somehow NSEC3/OptOut related. (an
NSEC zone, from the same signer, is working fine).

The command:

./drill -k root.key -DT ns1.dns.lu a

Last lines of the output:

;; Domain: dns.lu.
[T] dns.lu. 7200 IN DNSKEY 256 3 8 ;{id = 41485 (zsk), size = 1024b}
dns.lu. 7200 IN DNSKEY 256 3 8 ;{id = 16129 (zsk), size = 1024b}
dns.lu. 7200 IN DNSKEY 257 3 8 ;{id = 13736 (ksk), size = 2048b}
[B] Error verifying denial of existence for ns1.dns.lu. DS: General LDNS
;; No ds record for delegation
;; Domain: ns1.dns.lu.
;; No DNSKEY record found for ns1.dns.lu.
[T] ns1.dns.lu. 86400   IN      A

This is ldns 1.6.8.


Fondation RESTENA - DNS-LU
6, rue Coudenhove-Kalergi
L-1359 Luxembourg
tel: (+352) 424409
fax: (+352) 422473

More information about the ldns-users mailing list