DNSSEC + Split DNS

rob777 via Pdns-users <[email protected]> Thu, 9 Apr 2026 10:13:12 +0200
Newsgroups gmane.network.dns.powerdns.user
Message-ID <CAAPVCxygaFZvnrmekntj0fTiZuTg1J+N+sKBAk1-jeS5h667eA@mail.gmail.com>
--===============5423840157308568056==
Content-Type: multipart/alternative; boundary="00000000000012d7ca064f0297a2"

--00000000000012d7ca064f0297a2
Content-Type: text/plain; charset="UTF-8"

Hi

I have a Split DNS configuration:


*Internal DNS*
- I have an internal Setup of Powerdns Authoritative and Powerdns Recursor
- On the Powerdns Authorititative internal i have several internal only
domains like bla.test.com, bli.test.com etc. (configured via forward-zone)
- These internal Domains do not have dnssec configured
- My internal Servers and clients use the Powerdns Recursor to resolve
internal names via forward-zone and external Names via Recurso
(dnssec=validate active)


*External DNS*
- AWS R53 hosted Public Zone test.com
- DNSSEC is currently not enabled
- In the external test.com i have because of historical reasons some 2-3
shadow records (records which are also configured in the internal Zone on
Powerdns Authoritative with an internal IP...)

I'm planning to enable DNSSEC for the external test.com Zone (but for now
not on the internal Subdomains bla.test.com,bli.test.com etc. on the
internal Powerdns Authoritative).

I'm starting to believe that i will create a mess with enabling DNSSEC on
the external test.com side...i know that Split DNS is not optimal per se.

Do i create a mess with this planned DNSSEC enabling on the external
test.com DNS Zone?

Thanks for any advice

--00000000000012d7ca064f0297a2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi</div><div><br></div><div>I have a Split DNS config=
uration:</div><div><br></div><div><br></div><div><b>Internal DNS</b></div><=
div>- I have an internal Setup of Powerdns Authoritative and Powerdns Recur=
sor</div><div>- On the Powerdns Authorititative=C2=A0internal i have severa=
l internal only domains like <a href=3D"http://bla.test.com">bla.test.com</=
a>, <a href=3D"http://bli.test.com">bli.test.com</a> etc. (configured via f=
orward-zone)</div><div>- These internal Domains do not have dnssec configur=
ed</div><div>- My internal Servers and clients use the Powerdns Recursor to=
 resolve internal names via forward-zone and external Names via Recurso (dn=
ssec=3Dvalidate active)</div><div><br></div><div><br></div><div><b>External=
 DNS</b></div><div>- AWS R53 hosted Public Zone <a href=3D"http://test.com"=
>test.com</a></div><div>- DNSSEC is currently not enabled</div><div>- In th=
e external <a href=3D"http://test.com">test.com</a> i have because of histo=
rical reasons some 2-3 shadow records (records which are also configured in=
 the internal Zone on Powerdns Authoritative with an internal IP...)</div><=
div><br></div><div>I&#39;m planning to enable DNSSEC for the external <a hr=
ef=3D"http://test.com">test.com</a> Zone (but for now not on the internal S=
ubdomains <a href=3D"http://bla.test.com">bla.test.com</a>,<a href=3D"http:=
//bli.test.com">bli.test.com</a> etc. on the internal Powerdns Authoritativ=
e).</div><div><br></div><div>I&#39;m starting to believe that i will create=
 a mess with enabling DNSSEC on the external <a href=3D"http://test.com">te=
st.com</a> side...i know that Split DNS is not optimal per se.=C2=A0</div><=
div><br></div><div>Do i create a mess with this planned DNSSEC enabling on =
the external <a href=3D"http://test.com">test.com</a> DNS Zone?</div><div><=
br></div><div>Thanks for any advice</div><div><br></div><div><br></div></di=
v>

--00000000000012d7ca064f0297a2--

--===============5423840157308568056==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pdns-users mailing list
[email protected]
https://mailman.powerdns.com/mailman/listinfo/pdns-users

--===============5423840157308568056==--