It looks like the website certificate for wiki.opendnssec.org was renewed recently, but the TLSA record still references the old certificate. The Firefox DNSSEC/TLSA Validator plugin is thoroughly unhappy about that. Regards, Wytze van der Raay