2020-07-18 20:36:21 UTC
DNSSEC Authentication Chain

- redpilllinpro01.ring.nlnog.net/A
- redpilllinpro01.ring.nlnog.net/AAAA

- ./DNSKEY (alg 8, id 20326)
- ./DNSKEY (alg 8, id 46594)
- net/DNSKEY (alg 8, id 35886)
- net/DNSKEY (alg 8, id 36059)
- net/DNSKEY (alg 8, id 56519)
- net/DS (alg 8, id 35886)
- nlnog.net/DNSKEY (alg 13, id 14572)
- nlnog.net/DS (alg 13, id 14572)
- nlnog.net/DS (alg 13, id 14572)
- nlnog.net/DS (alg 13, id 14572)
- ring.nlnog.net/DNSKEY (alg 8, id 41746)
- ring.nlnog.net/DNSKEY (alg 8, id 45046)
- ring.nlnog.net/DNSKEY (alg 8, id 65139)
- ring.nlnog.net/DS (alg 8, id 41746)
- ring.nlnog.net/DS (alg 8, id 41746)
- ring.nlnog.net/DS (alg 8, id 41746)

- . to net
- net to nlnog.net
- nlnog.net to ring.nlnog.net

- nlnog.net/DS (alg 13, id 14572): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
- nlnog.net/DS (alg 13, id 14572): DNSSEC specification prohibits signing with DS records that use digest algorithm 3 (GOST 34.11-94).
- nlnog.net/DS (alg 13, id 14572): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
- nlnog.net/DS (alg 13, id 14572): Generating cryptographic hashes using algorithm 3 (GOST 34.11-94) is not supported by this code, so the cryptographic status of the DS RR is unknown.
- ring.nlnog.net/DS (alg 8, id 41746): DNSSEC specification prohibits signing with DS records that use digest algorithm 1 (SHA-1).
- ring.nlnog.net/DS (alg 8, id 41746): DNSSEC specification prohibits signing with DS records that use digest algorithm 3 (GOST 34.11-94).
- ring.nlnog.net/DS (alg 8, id 41746): DS records with digest type 1 (SHA-1) are ignored when DS records with digest type 2 (SHA-256) exist in the same RRset.
- ring.nlnog.net/DS (alg 8, id 41746): Generating cryptographic hashes using algorithm 3 (GOST 34.11-94) is not supported by this code, so the cryptographic status of the DS RR is unknown.
