Skip to content

Bug: DNSSEC validation failure for vpncloud.ddswd.de #388

Description

@mulder999

DNSSEC validation for vpncloud.ddswd.de fails in validating resolvers due to expired signatures in the ddswd.de zone, causing a broken trust chain.

Observed

  • delv vpncloud.ddswd.de → broken trust chain
  • Technitium DNS → SERVFAIL / NoReachableAuthority
  • A record still resolves via non-validating resolvers: 45.136.31.94
  • Verisign DNSSEC problems report

DNSSEC issue

  • Multiple RRSIG records are expired in ddswd.de
  • DNSKEY RRset cannot be validated
  • Authoritative servers return inconsistent DNSSEC results (some timeouts, some expired signatures)

Impact

DNSSEC-validating resolvers cannot resolve the domain.

Expected

Valid DNSSEC chain with fresh signatures so validating resolvers can resolve vpncloud.ddswd.de.

Suggested fix

Re-sign the ddswd.de zone and ensure all authoritative nameservers are synchronized with valid, non-expired DNSSEC records.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions