Brett, Thank you! It is fine now, and domain was just delegated with DNSSEC! Brett Carr wrote:
Max, sorry for the delay, we have now found and corrected a configuration error in our provisioning system. If you would care to resubmit your object containing the DS record it should now work without any problems.
Regards
Brett
-- Brett Carr Manager -- DNS Services Group RIPE Network Coordination Centre Amsterdam
On Jul 4, 2007, at 10:22 PM, Max Tulyev wrote:
Hi All,
I tried to create a DNSSEC signed backresolve domain for my IPv6 block:
domain: 0.d.0.0.1.0.a.2.ip6.arpa descr: NetAssist LLC org: ORG-NL64-RIPE admin-c: MT6561-RIPE tech-c: MT6561-RIPE zone-c: MT6561-RIPE nserver: ns.netassist.kiev.ua nserver: ns.netassist.ru ds-rdata: 46236 5 1 B42280F344BB12FCC5030673109EF84EF2C4D3A7 mnt-by: MEREZHA-MNT mnt-lower: MEREZHA-MNT changed: support@netassist.kiev.ua 20070704 source: RIPE
and it fails with:
***Error: DS records are not accepted for this zone.
***Error: RDNS Authorisation failed
but without ds-rdata everything works fine.
Is it a (my) bug or a feature?
--WBR, Max Tulyev (MT6561-RIPE, 2:463/253@FIDO)
-- Brett Carr Manager -- DNS Services Group RIPE Network Coordination Centre Amsterdam
-- WBR, Max Tulyev (MT6561-RIPE, 2:463/253@FIDO)