124.in-addr.arpa DNSSEC Outage: 2016-03-15

Updated: March 16, 2016

Overview

This page gives some details on the 124.in-addr.arpa DNSSEC outage on March 15, 2016. It was part of a huge APNIC DNSSEC outage.

Timeline / DNSViz

dns-operations list

This DNSSEC outage was discussed in the thread [dns-operations] APNIC reverse zone are broken.

apnic-talk list

The outage was acknowledged in the thread [apnic-talk] Update on APNIC IPv4 reverse DNS zones validation.

It was also discussed in [apnic-talk] APNIC reverse DNS zones validation.

Twitter

The @apnic Twitter account discussed the DNSSEC outage here and here.

OpenDNS vs. Google Public DNS

OpenDNS does not support DNSSEC, instead supporting DNSCurve. Google Public DNS currently supports only DNSSEC, and thus, Google's users saw SERVFAIL for queries under 124.in-addr.arpa during this outage.

With OpenDNS, queries succeed:

; <<>> DiG 9.4.2-P2 <<>> ns 124.in-addr.arpa @resolver1.opendns.com.
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 11772
;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;124.in-addr.arpa. IN NS

;; ANSWER SECTION:
124.in-addr.arpa. 86400 IN NS ns4.apnic.net.
124.in-addr.arpa. 86400 IN NS ns3.apnic.net.
124.in-addr.arpa. 86400 IN NS apnic.authdns.ripe.net.
124.in-addr.arpa. 86400 IN NS apnic1.dnsnode.net.
124.in-addr.arpa. 86400 IN NS ns1.apnic.net.
124.in-addr.arpa. 86400 IN NS tinnie.arin.net.
124.in-addr.arpa. 86400 IN NS ns2.lacnic.net.

;; Query time: 247 msec
;; SERVER: 208.67.222.222#53(208.67.222.222)
;; WHEN: Tue Mar 15 13:09:55 2016
;; MSG SIZE rcvd: 210


With Google Public DNS, because of DNSSEC, queries fail:

; <<>> DiG 9.4.2-P2 <<>> +dnssec ns 124.in-addr.arpa @8.8.8.8
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 50498
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 512
;; QUESTION SECTION:
;124.in-addr.arpa. IN NS

;; Query time: 82 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Tue Mar 15 13:09:55 2016
;; MSG SIZE rcvd: 45

Zonemaster

Zonemaster archived this 124.in-addr.arpa DNSSEC outage.

dnscheck

dnscheck.iis.se shows a broken DNSSEC delegation (requires javascript).

dnscheck.labs.nic.cz shows a broken DNSSEC delegation (requires javascript).

Logfile examples