• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Question DNSSEC - The TTL of the RRset exceeds the value of the Original TTL field of the RRSIG RR covering it

psxeu

Basic Pleskian
Server operating system version
Almalinux 9
Plesk version and microupdate number
Plesk Obsidian 18.0.67
Hi

I am setting DNSSEC up and are using a couple of online services to validate if everything is okay. One of the services are DNSViz | A DNS visualization tool - When I do it for a domain I get some errors:

RRSIG NSEC proving non-existence of MyDomain.tld/CDNSKEY alg 14, id 47160: The TTL of the RRset (10800) exceeds the value of the Original TTL field of the RRSIG RR covering it (7200). See RFC 4035, Sec. 2.2.

I can fix it by setting the Zone defaults TTL to 3 hours - but it seems more like a hack. Should the system not align the TTL for the RRset with the Zone defaults TTL?
 
I am not able to replicate this issue but then again I'm using Debian 12 instead of AlmaLinux. I'm wondering if this is something the registrar is doing?
 
Back
Top