I’m working on a project where I need to delegate a zone from one of my sites in Cloudflare. I’ve added NS and A/AAAA glue records in Cloudflare and the delegation works perfectly. The problem arises when I add the DS record for the delegation.
Using DiG, this is what I see:
dig @bella.ns.cloudflare.com slaac.tugzrida.xyz - returns the NS and glue records as expected
dig @bella.ns.cloudflare.com slaac.tugzrida.xyz +dnssec - dig times out
dig @bella.ns.cloudflare.com slaac.tugzrida.xyz ds - SERVFAIL
dig @bella.ns.cloudflare.com slaac.tugzrida.xyz ds +dnssec - dig times out
Basically, whenever the DS should be returned, the server times out or fails. I have tried this from my home connection, from which I reach server ID
SYD01, and from a Linode, from which I reach
SIN02, and achieve the same results from both.
I initially thought it might be an issue with my server(despite the fact that the delegation should be able to be served regardless of the child server), however I have run a packet capture and don’t see a single packet coming to my server from Cloudflare whilst attempting the above dig’s.
The DS record I added to Cloudflare is as follows:
Name: slaac.tugzrida.xyz Key tag: 16087 Algorithm: 13 Digest type: 2 Digest: DEBD7DBDB22FBF57D45AB2E9F26214C09D1A5F10AE5A1FBAB32224D662B9C638