Hi,
same problem here, Server 2012 R2 Essentials. The root trust anchors are deployed and everything is running fine except for some CNAMEs like support.microsoft.com. After the TTL is expired, DNS tries to get the DS-Records, which fails on Microsoft's nameservers.
Then, DNS sends a server failure (RCODE 2) to the client.
I have all updates installed. Any other workaround than completely disabling DNSSEC?
Here is an example of the communication:
24.02.2015 22:32:09 29AC PACKET 0000003E602EC240 UDP Rcv 192.168.2.155 20d3 Q [2001 D NOERROR] A (7)support(9)microsoft(3)com(0)
UDP question info at 0000003E602EC240
Socket = 524
Remote addr 192.168.2.155, port 65275
Time Query=948287, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x0032 (50)
Message:
XID 0x20d3
Flags 0x0120
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 1
RA 0
Z 0
CD 0
AD 1
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(7)support(9)microsoft(3)com(0)"
QTYPE A (1)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0027, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4096
TTL 0
DLEN 0
DATA
Buffer Size = 4096
Rcode Ext = 0
Rcode Full = 0
Version = 0
Flags = 0
24.02.2015 22:32:09 29AC PACKET 0000003E602D0160 UDP Snd 65.55.117.41 5e6a Q [1000 NOERROR] A (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP question info at 0000003E602D0160
Socket = 17080
Remote addr 65.55.117.41, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x003b (59)
Message:
XID 0x5e6a
Flags 0x0010
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
CD 1
AD 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE A (1)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0030, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 0
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E60E061B0 UDP Rcv 65.55.117.41 5e6a R Q [0084 A NOERROR] A (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP response info at 0000003E60E061B0
Socket = 17080
Remote addr 65.55.117.41, port 53
Time Query=948287, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x0062 (98)
Message:
XID 0x5e6a
Flags 0x8400
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 1
TC 0
RD 0
RA 0
Z 0
CD 0
AD 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 1
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE A (1)
QCLASS 1
ANSWER SECTION:
Offset = 0x0030, RR count = 0
Name "[C00C](11)smc-live-fe(14)trafficmanager(3)net(0)"
TYPE CNAME (5)
CLASS 1
TTL 300
DLEN 27
DATA (15)smc-live-neu-fe(8)cloudapp[C027](3)net(0)
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0057, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 0
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E60D861D0 UDP Snd 204.79.195.41 61e1 Q [1000 NOERROR] DS (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP question info at 0000003E60D861D0
Socket = 13056
Remote addr 204.79.195.41, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x003b (59)
Message:
XID 0x61e1
Flags 0x0010
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
CD 1
AD 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE DS (43)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0030, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 0
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E6059A110 UDP Rcv 204.79.195.41 61e1 R Q [0280 SERVFAIL] DS (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP response info at 0000003E6059A110
Socket = 13056
Remote addr 204.79.195.41, port 53
Time Query=948287, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x003b (59)
Message:
XID 0x61e1
Flags 0x8002
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
CD 0
AD 0
RCODE 2 (SERVFAIL)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE DS (43)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0030, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 2
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E60D861D0 UDP Snd 65.55.117.41 61e1 Q [1000 NOERROR] DS (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP question info at 0000003E60D861D0
Socket = 13056
Remote addr 65.55.117.41, port 53
Time Query=0, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x003b (59)
Message:
XID 0x61e1
Flags 0x0010
QR 0 (QUESTION)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
CD 1
AD 0
RCODE 0 (NOERROR)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE DS (43)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0030, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 0
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E605A6170 UDP Rcv 65.55.117.41 61e1 R Q [0280 SERVFAIL] DS (11)smc-live-fe(14)trafficmanager(3)net(0)
UDP response info at 0000003E605A6170
Socket = 13056
Remote addr 65.55.117.41, port 53
Time Query=948287, Queued=0, Expire=0
Buf length = 0x0fa0 (4000)
Msg length = 0x003b (59)
Message:
XID 0x61e1
Flags 0x8002
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 0
RA 0
Z 0
CD 0
AD 0
RCODE 2 (SERVFAIL)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(11)smc-live-fe(14)trafficmanager(3)net(0)"
QTYPE DS (43)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0030, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 32768
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 2
Version = 0
Flags = 80 DO
24.02.2015 22:32:09 29AC PACKET 0000003E602EC240 UDP Snd 192.168.2.155 20d3 R Q [8281 DR SERVFAIL] A (7)support(9)microsoft(3)com(0)
UDP response info at 0000003E602EC240
Socket = 524
Remote addr 192.168.2.155, port 65275
Time Query=948287, Queued=948287, Expire=948290
Buf length = 0x0fa0 (4000)
Msg length = 0x0032 (50)
Message:
XID 0x20d3
Flags 0x8182
QR 1 (RESPONSE)
OPCODE 0 (QUERY)
AA 0
TC 0
RD 1
RA 1
Z 0
CD 0
AD 0
RCODE 2 (SERVFAIL)
QCOUNT 1
ACOUNT 0
NSCOUNT 0
ARCOUNT 1
QUESTION SECTION:
Offset = 0x000c, RR count = 0
Name "(7)support(9)microsoft(3)com(0)"
QTYPE A (1)
QCLASS 1
ANSWER SECTION:
empty
AUTHORITY SECTION:
empty
ADDITIONAL SECTION:
Offset = 0x0027, RR count = 0
Name "(0)"
TYPE OPT (41)
CLASS 4000
TTL 0
DLEN 0
DATA
Buffer Size = 4000
Rcode Ext = 0
Rcode Full = 2
Version = 0
Flags = 0
Thanks & best regards