[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Anybody else having problems w/ DNSSEC and ftp.debian.org?

Stephane Bortzmeyer <bortzmeyer@nic.fr> (Di 14 Dez 2010 16:15:56 CET):
> On Tue, Dec 14, 2010 at 04:11:01PM +0100,
>  Heiko Schlittermann <hs@schlittermann.de> wrote 
>  a message of 65 lines which said:
> > > Expired signature ket in the cache, may be? It ends at
> > > 2010-12-14T09:48Z, which was several hours ago.
> > 
> > Sure? I'd say the signature expires 20110111094829 and was created
> > 20101214094829.
> Yes. You're right. Reply too fast and coffee too late. Sorry.

OK, but the question remains, what's going on here… Who is wrong?
Unfortunely nobody else responded. And on a DENIC DNSSEC mailing list I
got only vague clues too. There I (too fast?) wrote, it solved, since I
was able to reproduce it changing the bind versions.

BTW, this issue we have on two independent machines, both running a
recent lenny. One system is connected via T-Online, the other one has a
"real" uplink.

Both systems do not use any forwarder (they know about).

Heiko :: dresden : linux : SCHLITTERMAN.de
GPG Key 48D0359B : 3061 CFBF 2D88 F034 E8D2 7E92 EE4E AC98 48D0 359B

Attachment: signature.asc
Description: Digital signature

Reply to: