All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

DNSSEC Debugger Analysis of nic.de: Chain of Trust Verification

By

warpspin

26d ago· 4 min readenInsight

Summary

The DNSSEC Debugger tool from VeriSign Labs analyzes DNSSEC configuration problems for the domain nic.de. It checks DS records, RRSIGs, DNSKEY records, and their cryptographic chain of trust. The tool found 1 DS record for de in the root zone with algorithm RSASHA256, verified RRSIGs over the DS and DNSKEY RRsets, and identified 3 DNSKEY records for de. It also found 1 DS record for nic.de in the de zone. The tool flagged some unknown hosts (a.nic.de, l.de.net) during the analysis.

Key quotes

· 5 pulled
Found 1 DS records for de in the . zone
DS=26755/SHA-256 has algorithm RSASHA256
Found 1 RRSIGs over DS RRset
RRSIG=54393 and DNSKEY=54393 verifies the DS RRset
DS=26755/SHA-256 verifies DNSKEY=26755/SEP
Snippet from the RSS feed
The DNSSEC Debugger from VeriSign Labs is an on-line tool to assist with diagnosing problems with DNSSEC-signed names and zones.

You might also wanna read