DNSSEC + Split DNS
rob777 via Pdns-users <[email protected]> Thu, 9 Apr 2026 10:13:12 +0200
| Newsgroups | gmane.network.dns.powerdns.user |
|---|---|
| Message-ID | <CAAPVCxygaFZvnrmekntj0fTiZuTg1J+N+sKBAk1-jeS5h667eA@mail.gmail.com> |
--===============5423840157308568056== Content-Type: multipart/alternative; boundary="00000000000012d7ca064f0297a2" --00000000000012d7ca064f0297a2 Content-Type: text/plain; charset="UTF-8" Hi I have a Split DNS configuration: *Internal DNS* - I have an internal Setup of Powerdns Authoritative and Powerdns Recursor - On the Powerdns Authorititative internal i have several internal only domains like bla.test.com, bli.test.com etc. (configured via forward-zone) - These internal Domains do not have dnssec configured - My internal Servers and clients use the Powerdns Recursor to resolve internal names via forward-zone and external Names via Recurso (dnssec=validate active) *External DNS* - AWS R53 hosted Public Zone test.com - DNSSEC is currently not enabled - In the external test.com i have because of historical reasons some 2-3 shadow records (records which are also configured in the internal Zone on Powerdns Authoritative with an internal IP...) I'm planning to enable DNSSEC for the external test.com Zone (but for now not on the internal Subdomains bla.test.com,bli.test.com etc. on the internal Powerdns Authoritative). I'm starting to believe that i will create a mess with enabling DNSSEC on the external test.com side...i know that Split DNS is not optimal per se. Do i create a mess with this planned DNSSEC enabling on the external test.com DNS Zone? Thanks for any advice --00000000000012d7ca064f0297a2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi</div><div><br></div><div>I have a Split DNS config= uration:</div><div><br></div><div><br></div><div><b>Internal DNS</b></div><= div>- I have an internal Setup of Powerdns Authoritative and Powerdns Recur= sor</div><div>- On the Powerdns Authorititative=C2=A0internal i have severa= l internal only domains like <a href=3D"http://bla.test.com">bla.test.com</= a>, <a href=3D"http://bli.test.com">bli.test.com</a> etc. (configured via f= orward-zone)</div><div>- These internal Domains do not have dnssec configur= ed</div><div>- My internal Servers and clients use the Powerdns Recursor to= resolve internal names via forward-zone and external Names via Recurso (dn= ssec=3Dvalidate active)</div><div><br></div><div><br></div><div><b>External= DNS</b></div><div>- AWS R53 hosted Public Zone <a href=3D"http://test.com"= >test.com</a></div><div>- DNSSEC is currently not enabled</div><div>- In th= e external <a href=3D"http://test.com">test.com</a> i have because of histo= rical reasons some 2-3 shadow records (records which are also configured in= the internal Zone on Powerdns Authoritative with an internal IP...)</div><= div><br></div><div>I'm planning to enable DNSSEC for the external <a hr= ef=3D"http://test.com">test.com</a> Zone (but for now not on the internal S= ubdomains <a href=3D"http://bla.test.com">bla.test.com</a>,<a href=3D"http:= //bli.test.com">bli.test.com</a> etc. on the internal Powerdns Authoritativ= e).</div><div><br></div><div>I'm starting to believe that i will create= a mess with enabling DNSSEC on the external <a href=3D"http://test.com">te= st.com</a> side...i know that Split DNS is not optimal per se.=C2=A0</div><= div><br></div><div>Do i create a mess with this planned DNSSEC enabling on = the external <a href=3D"http://test.com">test.com</a> DNS Zone?</div><div><= br></div><div>Thanks for any advice</div><div><br></div><div><br></div></di= v> --00000000000012d7ca064f0297a2-- --===============5423840157308568056== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Pdns-users mailing list [email protected] https://mailman.powerdns.com/mailman/listinfo/pdns-users --===============5423840157308568056==--