Skip to content

Instantly share code, notes, and snippets.

@jpmens
Created September 19, 2017 15:03
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save jpmens/ea6bd86c813a80f20bcc6f8ca17803fd to your computer and use it in GitHub Desktop.
Save jpmens/ea6bd86c813a80f20bcc6f8ca17803fd to your computer and use it in GitHub Desktop.
Roll roll roll the key, gently down the stream
before:
; <<>> DiG 9.11.2 <<>> +norec +dnssec +multi . DNSKEY @a.root-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 32309
;; flags: qr aa; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 172800 IN DNSKEY 257 3 8 (
AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQ
bSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh
/RStIoO8g0NfnfL2MTJRkxoXbfDaUeVPQuYEhg37NZWA
JQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaDX6RS6CXp
oY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3
LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGO
Yl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGc
LmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0=
) ; KSK; alg = RSASHA256 ; key id = 19036
. 172800 IN DNSKEY 256 3 8 (
AwEAAYvxrQOOujKdZz+37P+oL4l7e35/0diH/mZITGjl
p4f81ZGQK42HNxSfkiSahinPR3t0YQhjC393NX4TorSi
TJy76TBWddNOkC/IaGqcb4erU+nQ75k2Lf0oIpA7qTCk
3UkzYBqhKDHHAr2UditE7uFLDcoX4nBLCoaH5FtfxhUq
yTlRu0RBXAEuKO+rORTFP0XgA5vlzVmXtwCkb9G8GknH
uO1jVAwu3syPRVHErIbaXs1+jahvWWL+Do4wd+lA+TL3
+pUk+zKTD2ncq7ZbJBZddo9T7PZjvntWJUzIHIMWZRFA
jpi+V7pgh0o1KYXZgDUbiA1s9oLAL1KLSdmoIYM=
) ; ZSK; alg = RSASHA256 ; key id = 15768
. 172800 IN DNSKEY 257 3 8 (
AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTO
iW1vkIbzxeF3+/4RgWOq7HrxRixHlFlExOLAJr5emLvN
7SWXgnLh4+B5xQlNVz8Og8kvArMtNROxVQuCaSnIDdD5
LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF0jLHwVN8
efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7
pr+eoZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLY
A4/ilBmSVIzuDWfdRUfhHdY6+cn8HFRm+2hM8AnXGXws
9555KrUB5qihylGa8subX2Nn6UwNR1AkUTV74bU=
) ; KSK; alg = RSASHA256 ; key id = 20326
. 172800 IN RRSIG DNSKEY 8 0 172800 (
20170930000000 20170909000000 19036 .
k68xiMgfi4yZCiX7GDRkpWXBEY5hHiUMUXnMaSgE3X1a
YpU/AQKHW7yQrOVXkSWwu5GSendgshSlqfwUxPK3xCg8
YqnulyNG5beQBFnNwPet0v2NsporNEg+rcSnWU+kTOZO
rj+ANySz94w0/8+JssLVhnbuEan27PYve14KE811HAPJ
fyrqrcT27fAA0PkfqiXvOpvC5zpG4Eei0D5TDNoalogh
OabkMO2xYyh56fa1He9PpRBGpygYZ1Wg4Hmne3kCBRec
70QoA1lkf2UYMVMeF8sijUIOUN7bfIEXWxECHceFztP2
hbg33zmW0zmzydn2KRt37wTuJa/z7hNfGA== )
;; Query time: 21 msec
;; SERVER: 2001:503:ba3e::2:30#53(2001:503:ba3e::2:30)
;; WHEN: Mon Sep 18 21:25:24 CEST 2017
;; MSG SIZE rcvd: 1139
after
;; Truncated, retrying in TCP mode.
; <<>> DiG 9.11.2 <<>> +multiline +norec +dnssec . DNSKEY @a.root-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47001
;; flags: qr aa; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 172800 IN DNSKEY 256 3 8 (
AwEAAcRIZfxskdElMKgjwvWQO2bQe7EGAvX6zgIaqmbs
aMqmMrIpd1+bP7nyULLuL8jWnKAqcaVfal2yJD50gg5z
Fl5yW/F9dKNXXEFI7VEcGrPyG6/OrA9RBU8pGWm0qxps
Nm5UIgTU5IX7pb/0rBj67c/R7qln8sjH1ylsr4f1Y3R6
p/druiEalKasEjGKA9L2w9jzUQusWxM7fQx/T8c/3x3b
sjveD1dleQ6MJaCx4bpPXYZpqXmSvGn+T2v5350cBVAF
qVKhGbjxEyXAweem8cTU4L1p+DV7Ua11a1tMf0Tlu8pk
pLwh7NQIggIEhJwEhPeXE3E4C6Q2/PFENcoFERc=
) ; ZSK; alg = RSASHA256 ; key id = 46809
. 172800 IN DNSKEY 257 3 8 (
AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQ
bSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh
/RStIoO8g0NfnfL2MTJRkxoXbfDaUeVPQuYEhg37NZWA
JQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaDX6RS6CXp
oY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3
LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGO
Yl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGc
LmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0=
) ; KSK; alg = RSASHA256 ; key id = 19036
. 172800 IN DNSKEY 256 3 8 (
AwEAAYvxrQOOujKdZz+37P+oL4l7e35/0diH/mZITGjl
p4f81ZGQK42HNxSfkiSahinPR3t0YQhjC393NX4TorSi
TJy76TBWddNOkC/IaGqcb4erU+nQ75k2Lf0oIpA7qTCk
3UkzYBqhKDHHAr2UditE7uFLDcoX4nBLCoaH5FtfxhUq
yTlRu0RBXAEuKO+rORTFP0XgA5vlzVmXtwCkb9G8GknH
uO1jVAwu3syPRVHErIbaXs1+jahvWWL+Do4wd+lA+TL3
+pUk+zKTD2ncq7ZbJBZddo9T7PZjvntWJUzIHIMWZRFA
jpi+V7pgh0o1KYXZgDUbiA1s9oLAL1KLSdmoIYM=
) ; ZSK; alg = RSASHA256 ; key id = 15768
. 172800 IN DNSKEY 257 3 8 (
AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTO
iW1vkIbzxeF3+/4RgWOq7HrxRixHlFlExOLAJr5emLvN
7SWXgnLh4+B5xQlNVz8Og8kvArMtNROxVQuCaSnIDdD5
LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF0jLHwVN8
efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7
pr+eoZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLY
A4/ilBmSVIzuDWfdRUfhHdY6+cn8HFRm+2hM8AnXGXws
9555KrUB5qihylGa8subX2Nn6UwNR1AkUTV74bU=
) ; KSK; alg = RSASHA256 ; key id = 20326
. 172800 IN RRSIG DNSKEY 8 0 172800 (
20171010000000 20170919000000 19036 .
G1B0YY5YGCRtT3HuZhR6/ivgiiZ5uBSkPri6Mrhz6lZt
JeQMeIPiIlAO+Y8jEkurNYPL4Gk1kaprSKBbKnB3joIe
GHGBBRiKYgS0cQk/NWuEX9JfLtW0RwZhrXTN7JsH15/W
EjFQkH0LnR+R3WUFH8uHR4kxLFKztKDSZoNf+PR7pa8P
K98YcjSW7rZcTV70V3daSwQTeJIpXpUhVUGXXju9WN0c
RVVYCk7sRteUqKqJQxLBAlzYQX2CgPhZOTypqJxzj12e
9Y/9WPGkBLqfxHms0c/Om+NO5WhNNONLdoXX8Yw4okFC
podGUO/UMrgM4qm7SWxXkjZwedzDZFJpYA== )
;; Query time: 21 msec
;; SERVER: 2001:503:ba3e::2:30#53(2001:503:ba3e::2:30)
;; WHEN: Tue Sep 19 16:52:09 CEST 2017
;; MSG SIZE rcvd: 1414
#
;; Truncated, retrying in TCP mode.
; <<>> DiG 9.11.2 <<>> +norec +dnssec . DNSKEY @a.root-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 40264
;; flags: qr aa; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 172800 IN DNSKEY 257 3 8 AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=
. 172800 IN DNSKEY 256 3 8 AwEAAYvxrQOOujKdZz+37P+oL4l7e35/0diH/mZITGjlp4f81ZGQK42H NxSfkiSahinPR3t0YQhjC393NX4TorSiTJy76TBWddNOkC/IaGqcb4er U+nQ75k2Lf0oIpA7qTCk3UkzYBqhKDHHAr2UditE7uFLDcoX4nBLCoaH 5FtfxhUqyTlRu0RBXAEuKO+rORTFP0XgA5vlzVmXtwCkb9G8GknHuO1j VAwu3syPRVHErIbaXs1+jahvWWL+Do4wd+lA+TL3+pUk+zKTD2ncq7Zb JBZddo9T7PZjvntWJUzIHIMWZRFAjpi+V7pgh0o1KYXZgDUbiA1s9oLA L1KLSdmoIYM=
. 172800 IN DNSKEY 257 3 8 AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3 +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF 0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN R1AkUTV74bU=
. 172800 IN RRSIG DNSKEY 8 0 172800 20170930000000 20170909000000 19036 . k68xiMgfi4yZCiX7GDRkpWXBEY5hHiUMUXnMaSgE3X1aYpU/AQKHW7yQ rOVXkSWwu5GSendgshSlqfwUxPK3xCg8YqnulyNG5beQBFnNwPet0v2N sporNEg+rcSnWU+kTOZOrj+ANySz94w0/8+JssLVhnbuEan27PYve14K E811HAPJfyrqrcT27fAA0PkfqiXvOpvC5zpG4Eei0D5TDNoaloghOabk MO2xYyh56fa1He9PpRBGpygYZ1Wg4Hmne3kCBRec70QoA1lkf2UYMVMe F8sijUIOUN7bfIEXWxECHceFztP2hbg33zmW0zmzydn2KRt37wTuJa/z 7hNfGA==
;; Query time: 22 msec
;; SERVER: 2001:503:ba3e::2:30#53(2001:503:ba3e::2:30)
;; WHEN: Tue Sep 19 15:59:28 CEST 2017
;; MSG SIZE rcvd: 1139
# after
;; Truncated, retrying in TCP mode.
; <<>> DiG 9.11.2 <<>> +norec +dnssec . DNSKEY @a.root-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 24421
;; flags: qr aa; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 1232
;; QUESTION SECTION:
;. IN DNSKEY
;; ANSWER SECTION:
. 172800 IN DNSKEY 256 3 8 AwEAAYvxrQOOujKdZz+37P+oL4l7e35/0diH/mZITGjlp4f81ZGQK42H NxSfkiSahinPR3t0YQhjC393NX4TorSiTJy76TBWddNOkC/IaGqcb4er U+nQ75k2Lf0oIpA7qTCk3UkzYBqhKDHHAr2UditE7uFLDcoX4nBLCoaH 5FtfxhUqyTlRu0RBXAEuKO+rORTFP0XgA5vlzVmXtwCkb9G8GknHuO1j VAwu3syPRVHErIbaXs1+jahvWWL+Do4wd+lA+TL3+pUk+zKTD2ncq7Zb JBZddo9T7PZjvntWJUzIHIMWZRFAjpi+V7pgh0o1KYXZgDUbiA1s9oLA L1KLSdmoIYM=
. 172800 IN DNSKEY 256 3 8 AwEAAcRIZfxskdElMKgjwvWQO2bQe7EGAvX6zgIaqmbsaMqmMrIpd1+b P7nyULLuL8jWnKAqcaVfal2yJD50gg5zFl5yW/F9dKNXXEFI7VEcGrPy G6/OrA9RBU8pGWm0qxpsNm5UIgTU5IX7pb/0rBj67c/R7qln8sjH1yls r4f1Y3R6p/druiEalKasEjGKA9L2w9jzUQusWxM7fQx/T8c/3x3bsjve D1dleQ6MJaCx4bpPXYZpqXmSvGn+T2v5350cBVAFqVKhGbjxEyXAweem 8cTU4L1p+DV7Ua11a1tMf0Tlu8pkpLwh7NQIggIEhJwEhPeXE3E4C6Q2 /PFENcoFERc=
. 172800 IN DNSKEY 257 3 8 AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=
. 172800 IN DNSKEY 257 3 8 AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3 +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF 0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN R1AkUTV74bU=
. 172800 IN RRSIG DNSKEY 8 0 172800 20171010000000 20170919000000 19036 . G1B0YY5YGCRtT3HuZhR6/ivgiiZ5uBSkPri6Mrhz6lZtJeQMeIPiIlAO +Y8jEkurNYPL4Gk1kaprSKBbKnB3joIeGHGBBRiKYgS0cQk/NWuEX9Jf LtW0RwZhrXTN7JsH15/WEjFQkH0LnR+R3WUFH8uHR4kxLFKztKDSZoNf +PR7pa8PK98YcjSW7rZcTV70V3daSwQTeJIpXpUhVUGXXju9WN0cRVVY Ck7sRteUqKqJQxLBAlzYQX2CgPhZOTypqJxzj12e9Y/9WPGkBLqfxHms 0c/Om+NO5WhNNONLdoXX8Yw4okFCpodGUO/UMrgM4qm7SWxXkjZwedzD ZFJpYA==
;; Query time: 26 msec
;; SERVER: 2001:503:ba3e::2:30#53(2001:503:ba3e::2:30)
;; WHEN: Tue Sep 19 15:59:50 CEST 2017
;; MSG SIZE rcvd: 1414
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment