View on GitHub

DNSViz: A DNS visualization tool

www.fi.muni.cz

DNSSEC options (hide)
  1. |?|
  2. |?|
  3. |?|
  4. |?|
  5. |?|
  6. |?|
  7. |?|
  8. |?|
  9. |?|
  10. |?|
Notices
DNSSEC Authentication Chain

RRset statusRRset status

Secure (4)
  • aisa.fi.muni.cz/A
  • aisa.fi.muni.cz/AAAA
  • fi.muni.cz/SOA
  • www.fi.muni.cz/CNAME

DNSKEY/DS/NSEC statusDNSKEY/DS/NSEC status

Bogus (1)
  • NSEC proving non-existence of fi.muni.cz/DS
Secure (10)
  • ./DNSKEY (alg 8, id 20326)
  • ./DNSKEY (alg 8, id 20826)
  • cz/DNSKEY (alg 13, id 20237)
  • cz/DNSKEY (alg 13, id 8659)
  • cz/DS (alg 13, id 20237)
  • fi.muni.cz/DNSKEY (alg 13, id 56292)
  • fi.muni.cz/DS (alg 13, id 56292)
  • muni.cz/DNSKEY (alg 13, id 50445)
  • muni.cz/DNSKEY (alg 13, id 5617)
  • muni.cz/DS (alg 13, id 50445)

Delegation statusDelegation status

Secure (3)
  • . to cz
  • cz to muni.cz
  • muni.cz to fi.muni.cz

NoticesNotices

Errors (6)
  • NSEC proving non-existence of fi.muni.cz/DS: The SOA bit was set in the bitmap of the NSEC RR corresponding to the delegated name (fi.muni.cz). See RFC 4034, Sec. 5.2.
  • NSEC proving non-existence of fi.muni.cz/DS: The SOA bit was set in the bitmap of the NSEC RR corresponding to the delegated name (fi.muni.cz). See RFC 4034, Sec. 5.2.
  • RRSIG NSEC proving non-existence of fi.muni.cz/DS alg 13, id 56292: The Signer's Name field of the RRSIG RR (fi.muni.cz) does not match the name of the zone containing the RRset (muni.cz). See RFC 4035, Sec. 5.3.1.
  • muni.cz to fi.muni.cz: An SOA RR with owner name (fi.muni.cz) not matching the zone name (muni.cz) was returned with the NODATA response. See RFC 1034, Sec. 4.3.4, RFC 2308, Sec. 2.2. (147.251.4.33, 2001:718:801:404::33, UDP_-_EDNS0_4096_D_KN)
  • muni.cz zone: The server(s) responded over UDP with a malformed response or with an invalid RCODE. See RFC 1035, Sec. 4.1.1. (147.251.4.33, 2001:718:801:404::33)
  • muni.cz/DNSKEY: The response had an invalid RCODE (SERVFAIL). See RFC 1035, Sec. 4.1.1. (147.251.4.33, 2001:718:801:404::33, UDP_-_EDNS0_512_D_KN, UDP_-_NOEDNS_)

DNSKEY legend

Full legend
SEP bit setSEP bit set
Revoke bit setRevoke bit set
Trust anchorTrust anchor
Download: png | svg
Warning JavaScript is required to make the graph below interactive.
DNSSEC authentication graph