2 ms·
I've checked, it's definitely signed: ; <<>> DiG 9.11.0-P1 <<>> ed25519.nl +dnssec ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY
by aeden 9y ago
I've checked, it's definitely signed:
; <<>> DiG 9.11.0-P1 <<>> ed25519.nl +dnssec
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 594
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 512
;; QUESTION SECTION:
;ed25519.nl. IN A
;; ANSWER SECTION:
ed25519.nl. 1341 IN RRSIG A 15 2 3600 20171012000000 20170921000000 27662 ed25519.nl. Z62ywpWQ4ahOs0DZxIs3OAY67qc226z6rs8k8q2i/hdwQAjz5EL5ZJke t25LD88wx5kGY5ru6Dvfrd7KvODCAg==
ed25519.nl. 1341 IN A 77.72.150.82
;; Query time: 55 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Wed Sep 27 20:44:46 EDT 2017
- teddyh 9y agoThe zone may be signed locally, but the DS records for ed25519.nl haven’t (when I checked myself just now) yet been exported into the TLD zone. It’s basically equivalent to a self-signed certificate. The lack of DS records in the TLD zone is the reason why WHOIS says "DNSSEC: no".
- Habbie 9y agoThe .nl registry does not support algo 15 (and 16) for DS records yet. Support is expected soon.