Why DNSSEC Issues (bad cache hit/insecurity proof) error comes?
Issue
- Insecurity proof failed
Dec 19 10:49:49 hostname1 named[25995]: error (insecurity proof failed) resolving 'example1.com/DNSKEY/IN': X.X.X.X#53
Dec 19 10:49:50 hostname1 named[25995]: error (insecurity proof failed) resolving 'example2.com/A/IN': Y.Y.Y.Y#53
Dec 19 10:49:50 hostname1 named[25995]: error (insecurity proof failed) resolving 'example2.com/A/IN': Z.Z.Z.Z#53
Dec 19 10:49:07 hostname1 named[25995]: validating @0x7fb034724be0: test.example3.com A: bad cache hit
Dec 19 10:49:07 dnssec: info: validating @35944ae8: mg.mail.example.com A: bad cache hit (example.com/DS)
Dec 19 10:49:07 dnssec: info: validating @38f68a70: pr-apac.ybp.example.com A: bad cache hit (example.com/DS)
Dec19 11:12:04.399 dnssec: info: validating @2445f0f8: mail.example.in NSEC: no valid signature found
Environment
*Red Hat Enterprise Linux 5
*Red Hat Enterprise Linux 6
* Bind-dnssec
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.