1.1.1.1 can't reach US .mil websites


#1

Hello,

I use https://www.dibbs.bsm.dla.mil/ for work, but I can’t reach any of the .mil sites when using 1.1.1.1.

They all work with 8.8.8.8

tia


#2

I believe the issue is already known to the team.

But a new case is never bad as there are more info, would you mind following this?


#3

Is there a way to get an ETA? I’ve been checking every 2 weeks but the issue persist.


#4

Will have to wait on @cscharff on Monday I presume…


#5

I believe this probably the same root cause and is being addressed in a code change to the resolver in use itself:

Appreciate the additional data point though and have linked this thread to our internal tracking so we can update when a resolution is available.


#6

heh… checking in before I head out for the day.


#7

So, you work on Saturdays too, have a great weekend!


#8

Hi, the problem is that the www.dibbs.bsm.dla.mil in bsm.dla.mil zone has broken DNSSEC, so validating DNS resolvers will block the answer. We’ll try to reach out.

http://dnsviz.net/d/www.dibbs.bsm.dla.mil/dnssec/