. to ss: No valid RRSIGs made by a key corresponding to a DS RR were found covering the DNSKEY RRset, resulting in no secure entry point (SEP) into the zone. See RFC 4035, Sec. 2.2, RFC 6840, Sec. 5.11. (196.216.168.27, UDP_-_EDNS0_4096_D_KN)
RRSIG ss/DNSKEY alg 8, id 39884: The Signature Expiration field of the RRSIG RR (2024-10-24 08:01:28+00:00) is 5 days in the past. See RFC 4035, Sec. 5.3.1.
RRSIG ss/DNSKEY alg 8, id 39884: The Signature Expiration field of the RRSIG RR (2024-10-24 08:01:28+00:00) is 5 days in the past. See RFC 4035, Sec. 5.3.1.
RRSIG ss/DNSKEY alg 8, id 39884: The Signature Expiration field of the RRSIG RR (2024-10-24 08:01:28+00:00) is 5 days in the past. See RFC 4035, Sec. 5.3.1.
RRSIG ss/NS alg 8, id 51501: The Signature Expiration field of the RRSIG RR (2024-10-24 08:01:28+00:00) is 5 days in the past. See RFC 4035, Sec. 5.3.1.
RRSIG ss/NSEC3PARAM alg 8, id 51501: The Signature Expiration field of the RRSIG RR (2024-10-24 08:01:28+00:00) is 5 days in the past. See RFC 4035, Sec. 5.3.1.
ss/CDS has errors; select the "Denial of existence" DNSSEC option to see them.
ss/CDNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
ss/DNSKEY has errors; select the "Denial of existence" DNSSEC option to see them.
ss/CNAME has errors; select the "Denial of existence" DNSSEC option to see them.