Ask Your Question

DNSSEC response marked as Malformed

asked 2018-10-18 12:45:53 +0000

tobias.gruenewald gravatar image

updated 2018-10-18 12:53:22 +0000

I am currently investigating an issue with Windows DNS Servers not working when DNSSEC is enabled and the server is configured to use a forwarder (another Windows DNS) for resolving. Windows Event log states, that DNS Server cannot perform an active refresh of the DNSKEY records of the root zone.

To dig into the issue I performed a Wireshark capture and found the requests and responses for the DNSKEY records. I captured the query/response from my DNS server to the forwarder as well as the same communication to a public DNS when the forwarder is disabled. Unfortunately I cannot attach the capture here, is posting a link allowed? (

The DNS response from the forwarder server is "malformed" according to the Wireshark packet dissector, which would explain the DNS server event. However it does not state in which way the packet is "malformed". So I manually followed the RFCs to identify and dissect all the fields of the DNS response by hand. I can see only a few differences, none of which look critical or non-RFC-compliant to me:

  • "malformed" response does not contain an RRSIG record
  • "malformed" response announces a longer UDP payload size in the EDNS OPT Record
  • "malformed" response has a different ordering of the returned DNSKEY records
  • "malformed" answer records names are a reference 0xC00C instead of the name of the root zone 0x00

I would like to understand, if something is really wrong with the DNS response, which would explain the server problems, or if the response itself is ok and only the DNS dissector of WIreshark is not working correctly.

Wireshark is version 2.6.4 (v2.6.4-0-g29d48ec8) for Windows

image description

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2018-10-20 16:49:05 +0000

Jaap gravatar image

You seen to have stumbled upon bug 15574 which was fixed in the main development branch. This fix has now been back ported to 2.6, therefore will be available with the next maintenance release of 2.6, in about a month.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2018-10-18 12:45:53 +0000

Seen: 4,309 times

Last updated: Oct 20 '18