Skip to content

Why does DNSSEC still break transfers in 2024?

Domain Names by marcus_qc 17 replies 8.5K views
#1

DNSSEC-signed domain at some registrar, trying to push to us at InterServer. Stuck in "pending transfer" for 4 days. Root cause? DS record at old registrar still live, new registrar can't push without removal, old registrar's "automated" system doesn't auto-remove on outgoing transfer.

Super stoked to figure this out manually but c'mon, it's 2024 lol. Anyone else hitting this?

Workarounds I found:

  • Remove DS before initiating transfer (duh, but who remembers)
  • Some registrars have "disable DNSSEC" checkbox hidden in advanced
  • Wait for TTL + propagation + prayer

Mistake on my end: didn't catch this in our docs. Fixing now.

42U and still growing
#2

I am try transfer yesterday lah my.dev domain xixixi DS record it am make problem very long time I am click disable but it no work very ast xixixi you must wait propagation lah I am buy at Hetzner they say automatic xixixi

#3

Oh this is rich (coming from someone who once spent a week (no, really (a full seven days)) debugging what turned out to be a single NSEC3 parameter) (the automation angle is the real joke here) (because of course "automation" means "you do it manually but with extra steps") (I assume Hetzner's "automatic" is the same as my "automatic" coffee maker (I still have to grind the beans))

push. done. coffee.
#4

The dnssec thing Hetzner says autoamted but I trnasfered to them last mnth had 2 remove DS mysel they're lyign abotu full auto you figure it out he says runs together sometimes I refuse to edit this

#5
tomhider said:
The dnssec thing Hetzner says autoamted but I trnasfered to them last mnth had 2 remove DS mysel they're lyign abotu full auto you figure...

I moved a client to Hetzner last month and hit the same wall. Their DNSSEC transfer isn't fully automated — I had to remove the DS record myself before things would go through. Took about half a day of back-and-forth with their docs to figure out why it was stuck.

What they actually do:

  • Incoming transfers: DS records published automatically once they verify the zone
  • Outgoing transfers: DS removal needs manual authorization, which they say is ICANN policy
  • Pending state: sat there 4-6 hours after I authorized it

Their docs could be clearer about the manual step. Not the end of the world, but "full auto" it ain't.

#6

SNAPPED UP a.net for $12/YR ARE YOU KIDDING but DNSSEC transfer took 3 DAYS vs 45 minutes normal price history on this TLD is WILD but the hidden cost is your SANITY

world record: 4min Arch install
8 #7

Just use unsigned zones skill issue

Seriously though the real problem is registrars pretending DNSSEC is "set and forget" when it's actually "set and occasionally perform manual surgery"

If your automation can't handle DS removal on outbound transfer you don't have automation you have a GUI that lies

oops: 0000 [#1] SMP
#8

Hetzner pulled the same stunt on me last month. "Automatic" my ass

#9

Hetzner "automatic" is just you clicking buttons with extra waiting

/dev/null: full of good ideas
#10

Annexbi] I still have to grind the beans

This is exactly it, the grinding is the "disable" button that doesn't actually disable anything until you also find the second hidden "confirm disable" toggle

Hetzner's panel has a "DNSSEC Management" section that looks like a big off switch but it's just a status light, the real control is under "Advanced > Domain Security > Key Management" three menus deep and even then it queues a "pending removal" state for 24 hours

So your automatic coffee maker at least produces coffee, this produces a ticket number

Has anyone actually seen a registrar that handles outgoing DS removal properly without manual intervention? InterServer's inbound side is clean but I don't know if we auto-clear on outgoing transfers, might be worth checking if anyone here knows

/dev/null: full of good ideas

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft