Re: DNSSEC and DLZ

Mark Goldfinch <[email protected]> Thu, 31 Dec 2015 16:15:20 +1300
Newsgroups gmane.network.dns.bind9.dlz
Message-ID <CAK7eGc2W_Mpezp=_8TLvBbe0dtYQS2OcpgBuS2dC4iDrjHggrA@mail.gmail.com>
--===============5685673915315401172==
Content-Type: multipart/alternative; boundary=001a114a4892945cc40528291097

--001a114a4892945cc40528291097
Content-Type: text/plain; charset=UTF-8

Alternatively you will need to flow your DNS zone data through a system
like OpenDNSSec before publishing it within your DLZ Bind database.
On 31 Dec 2015 4:04 p.m., "Evan Hunt" <[email protected]> wrote:

> > I am using BIND with the DLZ driver from a while. The version I am using
> > is 9.10.2-P3.  I am trying to enable the DNSSEC feature, but I can't find
> > a way to have it working with DLZ.From the posts I read in the bind-users
> > mailing list, it sounds that DNSSEC is not supported yet in DLZ.  Inside
> > the file README in the folder contrib/dlz, I can't find any reference
> > (callback function) to DNSSEC.Does someone have any news/hints about this
> > topic?
>
> DLZ has no DNSSEC support.
>
> To generate a DNSSEC signed version of a DLZ zone, you could configure
> it as a hidden master, then use inline-signing on a slave.  The slave
> would transfer the zone in from the DLZ master and sign it.
>
> --
> Evan Hunt -- [email protected]
> Internet Systems Consortium, Inc.
>
>
> ------------------------------------------------------------------------------
> _______________________________________________
> Bind-dlz-testers mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers
>

--001a114a4892945cc40528291097
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">Alternatively you will need to flow your DNS zone data throu=
gh a system like OpenDNSSec before publishing it within your DLZ Bind datab=
ase.</p>
<div class=3D"gmail_quote">On 31 Dec 2015 4:04 p.m., &quot;Evan Hunt&quot; =
&lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br type=3D"=
attribution"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;b=
order-left:1px #ccc solid;padding-left:1ex">&gt; I am using BIND with the D=
LZ driver from a while. The version I am using<br>
&gt; is 9.10.2-P3.=C2=A0 I am trying to enable the DNSSEC feature, but I ca=
n&#39;t find<br>
&gt; a way to have it working with DLZ.From the posts I read in the bind-us=
ers<br>
&gt; mailing list, it sounds that DNSSEC is not supported yet in DLZ.=C2=A0=
 Inside<br>
&gt; the file README in the folder contrib/dlz, I can&#39;t find any refere=
nce<br>
&gt; (callback function) to DNSSEC.Does someone have any news/hints about t=
his<br>
&gt; topic?<br>
<br>
DLZ has no DNSSEC support.<br>
<br>
To generate a DNSSEC signed version of a DLZ zone, you could configure<br>
it as a hidden master, then use inline-signing on a slave.=C2=A0 The slave<=
br>
would transfer the zone in from the DLZ master and sign it.<br>
<br>
--<br>
Evan Hunt -- <a href=3D"mailto:[email protected]">[email protected]</a><br>
Internet Systems Consortium, Inc.<br>
<br>
---------------------------------------------------------------------------=
---<br>
_______________________________________________<br>
Bind-dlz-testers mailing list<br>
<a href=3D"mailto:[email protected]">Bind-dlz-testers@=
lists.sourceforge.net</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers" r=
el=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/lis=
tinfo/bind-dlz-testers</a><br>
</blockquote></div>

--001a114a4892945cc40528291097--


--===============5685673915315401172==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------

--===============5685673915315401172==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Bind-dlz-testers mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/bind-dlz-testers

--===============5685673915315401172==--