Re: bind-dlz and DNSSEC
Rob Butler <[email protected]> Tue, 27 Apr 2010 07:07:41 -0700 (PDT)
| Newsgroups | gmane.network.dns.bind9.dlz |
|---|---|
| Message-ID | <[email protected]> |
DNSSEC is primarily about creating the correct records in the zone. It may "just work" with DLZ. Try creating a standard zone and signing it with the existing dnssec tools. Then import those records into a DLZ DB and see if it works or not. The only reason it wouldn't work is if Bind has extra requirements on the format of the DNS records internally. Unfortunately, in Bind 9 they didn't think too deeply about proper data source boundaries and pluggable implementations. This resulted in some important processing existing within the Bind in-memory DB implementation instead of being in other places in Bind. Supporting pluggable data sources and dynamic back ends seems to be one of the primary drivers behind Bind 10. It has built in support for SQLite. I expect once Bind 10 is complete DLZ may no longer be necessary, or may just provide drivers for alternate data sources. Rob ----- Original Message ---- > From: Drew Broadley <[email protected]> > To: [email protected] > Sent: Mon, April 26, 2010 6:13:19 PM > Subject: [Bind-dlz-testers] bind-dlz and DNSSEC > > Hi all, We're running a few instances of bind-dlz, and we're being > pressured to reply with IDN (Internationalized Domain Names) and DNSSEC > compatibility with our current authoritative name server > installations. I've searched through the mailing list archives, I cannot > find any documented entries of DNSSEC in bind-dlz, or any feature requests. Is > this on the to-do list, or has someone offered any patch files to enable this > ? I can only find hearsay and other non-offical lines of comments in > regards to this, and would greatly appreciate some > clarity. Thanks, Drew Broadley > href="http://www.modicagroup.com">www.modicagroup.com ------------------------------------------------------------------------------ _______________________________________________ Bind-dlz-testers > mailing list > href="mailto:[email protected]">[email protected] > href="https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers" > target=_blank > >https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers ------------------------------------------------------------------------------