[Opendnssec-user] ods-signerd error parsing RR's data

Yuri Schaeffer yuri at nlnetlabs.nl
Thu Aug 6 12:13:53 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Paul,

If you are able to share that record (perhaps including the line
before and after), we can have a look. Off list ofcourse is fine.

Regards,
Yuri

On 06-08-15 13:54, Paul Duffy wrote:
> Matthijs,
> 
> Thanks for the note, when I run it through ldns-read-zone, it
> prints following:
> 
> # ldns-read-zone ie.zone.2015080509 Syntax error, could not parse
> the RR's rdata at 505631
> 
> # ldns-read-zone -v read zone version 1.6.17 (ldns version 1.6.17)
> 
> 
> I’ve had a look at the line via vim (showing unprintable
> characters) there’s nothing visually distinctive about it compare
> to other DS records so I’m at loss to explain what’s going on.
> 
> Now the above is on RHEL 6.7, as a matter of interest I decided to
> give it a shot on RHEL7 text box I have. The error is somewhat
> different, though still equally terse:
> 
> # ldns-verify-zone ie.zone.2015080509 General memory error at
> 505631
> 
> # ldns-verify-zone -v verify-zone version 1.6.16 (ldns version
> 1.6.16)
> 
> 
> 
> Regards -Paul
> 
> -- Paul Duffy Network Operations IE Domain Registry Ltd Tel: +353
> (1) 2365416 Fax: +353 (1) 2300365 Web: www.iedr.ie
> <http://www.iedr.ie>
> 
> ----------------------------------------------------------------------
- --------------
>
> 
Registered Office: Fourth Floor, Block 2, Harbour Square,
> Dun Laoghaire, Co. Dublin. Registered in Ireland. No: 315315 
> ----------------------------------------------------------------------
- --------------
>
> 
- ------------------------------------------------------------------------
- ------------
> The enclosed document is CONFIDENTIAL to addressee and IE Domain
> Registry Ltd. The intended addressee is NOT AUTHORISED to copy,
> distribute, disclose or otherwise use the information disclosed.
> Please also note that this information should not be edited or
> redistributed in any way. 
> ----------------------------------------------------------------------
- --------------
>
> 
> 
> 
> 
>> On 6 Aug 2015, at 11:47, Matthijs Mekking
>> <matthijs at pletterpet.nl <mailto:matthijs at pletterpet.nl>> wrote:
>> 
>> Hi Paul,
>> 
>> Try running the zone or RR through ldns-read-zone or some other
>> ldns example tool (OpenDNSSEC uses ldns to read in zones), maybe
>> that will help to gain some clue.
>> 
>> Best regards, Matthijs
>> 
>> On 06-08-15 12:16, Paul Duffy wrote:
>>> Hi,
>>> 
>>> Yesterday I ran into an issue when it came to signing zone. We
>>> had added a new DS record into our zone, when it came to
>>> signing the zone it choked when it hit this record:
>>> 
>>> ods-signerd: [adapter] error parsing RR at line 505591 (Syntax 
>>> error, could not parse the RR's rdata): snafu.ie
>>> <http://snafu.ie> <http://snafu.ie>.#011IN#011DS#01135791 5 1 
>>> 8B1EEDA983F93F36F69D4D165F079P51C8071B1D
>>> 
>>> 
>>> Now as far as I can tell there was nothing invalid per-say
>>> which this compare to any of the other DS’s that are in the
>>> zone. I had ran through a number of verification steps
>>> beforehand and verified that the DS match with what was
>>> published on the client domain’s (redacted - changed to 
>>> snafu.ie <http://snafu.ie> <http://snafu.ie>)  own name
>>> servers. When I got them to roll their KSK and submit new DS
>>> record it worked fine and didn’t cause any issue with ODS, so
>>> I’m bit perplexed. Any feedback/help would be appreciated.
>>> 
>>> (ods-signerd 1.4.6)
>>> 
>>> -Paul
>>> 
>>> -- Paul Duffy Network Operations IE Domain Registry Ltd Tel:
>>> +353 (1) 2365416 Fax: +353 (1) 2300365 Web: www.iedr.ie
>>> <http://www.iedr.ie> <http://www.iedr.ie>
>>> 
>>> --------------------------------------------------------------------
- ----------------
>>>
>>> 
Registered Office: Fourth Floor, Block 2, Harbour Square,
>>> Dun Laoghaire, Co. Dublin. Registered in Ireland. No: 315315 
>>> --------------------------------------------------------------------
- ----------------
>>>
>>> 
- ------------------------------------------------------------------------
- ------------
>>> The enclosed document is CONFIDENTIAL to addressee and IE
>>> Domain Registry Ltd. The intended addressee is NOT AUTHORISED
>>> to copy, distribute, disclose or otherwise use the information
>>> disclosed. Please also note that this information should not be
>>> edited or redistributed in any way. 
>>> --------------------------------------------------------------------
- ----------------
>>>
>>>
>>>
>>>
>>>
>>>
>>>
>>> 
_______________________________________________
>>> Opendnssec-user mailing list 
>>> Opendnssec-user at lists.opendnssec.org 
>>> <mailto:Opendnssec-user at lists.opendnssec.org> 
>>> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
>>> 
>> 
>> _______________________________________________ Opendnssec-user
>> mailing list Opendnssec-user at lists.opendnssec.org 
>> <mailto:Opendnssec-user at lists.opendnssec.org> 
>> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
> 
> 
> 
> _______________________________________________ Opendnssec-user
> mailing list Opendnssec-user at lists.opendnssec.org 
> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iEYEARECAAYFAlXDT4EACgkQI3PTR4mhaviDrwCffvo2hOT+3GfTVsfx1747JiZ9
QFYAnRJjVxhtQOaXqXLLzpEWaaQMRa2s
=UM80
-----END PGP SIGNATURE-----



More information about the Opendnssec-user mailing list