intentional bad DNSSEC and NSEC3

"Michael A. Peters" <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
Hello list,

I am attempting to create a single record in a zone file that will not 
DNSSEC validate. The purpose of this is to give myself a means of 
checking DNSSEC validation on my local systems.

What I am doing is creating both an A and AAAA record with the name 
ffinvalid and then after signing the zone, using sed to change ffinvalid 
to invalid.

What I don't know is what impact, if any, that will have on NSEC3 
records. Will that break by NSEC3 records?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.