org to sf-lug.org: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (50.18.139.240, 50.242.105.52, 96.86.170.229, 96.95.217.99, 2001:470:1f05:19e::3, 2600:1f1c:528:c500:5e0b:8a37:6598:356c, 2603:3024:180d:f100:50:242:105:34, UDP_-_EDNS0_4096_D_KN)
org to sf-lug.org: The DS RRset for the zone included algorithm 8 (RSASHA256), but no DS RR matched a DNSKEY with algorithm 8 that signs the zone's DNSKEY RRset. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (50.18.139.240, 50.242.105.52, 96.86.170.229, 96.95.217.99, 2001:470:1f05:19e::3, 2600:1f1c:528:c500:5e0b:8a37:6598:356c, 2603:3024:180d:f100:50:242:105:34, UDP_-_EDNS0_4096_D_KN)