os3sec / Extended-DNSSEC-Validator

Firefox add-on for verification of x509 certificates using DNSSEC as bootstrap mechanism
http://os3sec.org
15 stars 9 forks source link

Correctly signed DNSSEC records reported as invalid #16

Open mrnerdhair opened 11 years ago

mrnerdhair commented 11 years ago

I noticed this several months ago, and figured it was just my setup, but now I've updated to 0.8, noticed the same problem with my install of dnssec-trigger (which uses unbound as well), and noticed a comment on https://addons.mozilla.org/en-US/firefox/addon/extended-dnssec-validator/reviews/ that complains of an invalid signature on mozilla.com, so I figure I'd better get responsible and file a report.

Here are two sites I'm sure have valid signatures, but are being reported as insecure:

thing1 thing2

I've tried using my local validating resolver, my ISP's upstream resolver, and the Google public DNS service. No luck.