centos dnssec 확인 문제

centos dnssec 확인 문제

Centos 7dig 명령 예제를 시도하면 DNS 서버를 캐싱하는 데 문제가 있습니다.

dig www.google.com

나는이 출력을 얻습니다

; <<>> DiG 9.9.4-RedHat-9.9.4-29.el7 <<>> www.google.fr
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 54269
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;www.google.fr.                 IN      A

;; Query time: 0 msec
;; SERVER: 192.168.0.100#53(192.168.0.100)
;; WHEN: Wed Dec 14 06:26:02 CET 2016
;; MSG SIZE  rcvd: 42

하지만 /etc/named.conf에서 dnssec-validation을 no로 변경하면 제대로 작동합니다. 어떤 도움이라도

dig www.google.com

나는이 출력을 얻습니다

dig google.com


; <<>> DiG 9.9.4-RedHat-9.9.4-29.el7 <<>> google.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39355
;; flags: qr rd ra; QUERY: 1, ANSWER: 16, AUTHORITY: 13, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;google.com.                    IN      A

;; ANSWER SECTION:
google.com.             92      IN      A       41.201.129.30
google.com.             92      IN      A       41.201.129.54
google.com.             92      IN      A       41.201.129.29
google.com.             92      IN      A       41.201.129.25
google.com.             92      IN      A       41.201.129.50
google.com.             92      IN      A       41.201.129.59
google.com.             92      IN      A       41.201.129.24
google.com.             92      IN      A       41.201.129.40
google.com.             92      IN      A       41.201.129.34
google.com.             92      IN      A       41.201.129.44
google.com.             92      IN      A       41.201.129.20
google.com.             92      IN      A       41.201.129.45
google.com.             92      IN      A       41.201.129.49
google.com.             92      IN      A       41.201.129.39
google.com.             92      IN      A       41.201.129.35
google.com.             92      IN      A       41.201.129.55

;; AUTHORITY SECTION:
.                       169937  IN      NS      c.root-servers.net.
.                       169937  IN      NS      m.root-servers.net.
.                       169937  IN      NS      e.root-servers.net.
.                       169937  IN      NS      i.root-servers.net.
.                       169937  IN      NS      j.root-servers.net.
.                       169937  IN      NS      b.root-servers.net.
.                       169937  IN      NS      g.root-servers.net.
.                       169937  IN      NS      h.root-servers.net.
.                       169937  IN      NS      k.root-servers.net.
.                       169937  IN      NS      a.root-servers.net.
.                       169937  IN      NS      l.root-servers.net.
.                       169937  IN      NS      f.root-servers.net.
.                       169937  IN      NS      d.root-servers.net.

;; Query time: 85 msec
;; SERVER: 192.168.0.100#53(192.168.0.100)
;; WHEN: Wed Dec 14 04:44:52 CET 2016
;; MSG SIZE  rcvd: 506

답변1

모든 사람에게 문제가 해결되었음을 알리고 싶습니다. 내 연구실은 Vmware Workstation 12에 있지만 Kvm으로 옮겼을 때 모든 것이 잘 작동했고 바인딩 해제 및 명명이 모두 예상대로 작동했으며 명명된 dnssec-validation을 끌 필요가 없었습니다. .

관련 정보