[Opendnssec-user] "expected covering NSEC3, got an exact match" ?

Peter Olsson pol at leissner.se
Wed Dec 28 11:55:37 UTC 2011

Anyone know the reason for this message?
It started showing in our syslog a while back.
We get about 50 of these per day, from different
client IP. Do they mean that we have some problem
with our signed zones?

Google doesn't give much information about this
message in recent bind versions, other than that
it could be because of stale NSEC3 records.
But our signing process seems fine, and all
signatures are current.

