Re: DNS name creation [Was: Comments on multi6dt documents]
Jeroen Massar <[email protected]> Wed, 10 Nov 2004 17:32:29 +0100
| Newsgroups | gmane.ietf.multi6 |
|---|---|
| Organization | Unfix |
| Message-ID | <[email protected]> |
On Wed, 2004-11-10 at 17:16 +0100, Francis Dupont wrote: > About DDNS and DNSSEC: they don't work well together because DDNS > requires private (zone) keys are online to update signatures when > DNSSEC works well and safer with offline keys. > > Regards > > [email protected] > > PS: I locally solved this operational issue with a dedicated DDNS sub-zone. I guess this is the solution used in most cases. Many people like the format of their zones and ddns updates destroy the formatting of the zones file (at least bind does this). Thus you make CNAMES from the main zone to the subzone without bothering the clean zone. Isn't this part of an RFC or BCP actually? Greets, Jeroen
signature.asc
(application/pgp-signature, 240 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) Comment: Jeroen Massar / http://unfix.org/~jeroen/ iD8DBQBBkkKdKaooUjM+fCMRAg7cAJ9u5EJcO6xk7dnnBho47HcK6UJOggCfQAVQ Dsb2Pmc4Lzon50KYUBCsIzI= =trDh -----END PGP SIGNATURE-----