Re: Migration to inline-signing

Michael Richardson <[email protected]>
Newsgroups gmane.network.dns.bind9.user
Message-ID <15691.1747492501__39273.2869180449$1747492528$gmane$org@obiwan.sandelman.ca>
Crist Clark <[email protected]> wrote:
    > Tired of looking at the log messages warning me that inline-signing
    > will be the default in 9.20. I want to convert my 9.18 to using
    > inline-signing.  Right now all of the zones use dnssec-policy and are
    > dynamic.

My experience was that it was best to do bump-in-the-xfer signing.
I created a view "authoritative" loaded all my zones there, then created a
view called "signing", and had the signing view xfer, do-managed-signing, and
serving it.

I have a blog entry somewhere on this, which I can't locate right now.
-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.