Mark Andrews writes:
> 
> In message <[email protected]>, [email protected] 
> writes:
> > I do not want any dynamic DNS to my BIND servers, as I am not sure
> > how that DDNS would interface with DNSSEC.
> 
> DNSSEC is easier with a DDNS zone than a non-DDNS zone as named
> can ensure the signatures get re-generated when required.
> 9.6.0 onwards.

The main thing is to tell named where the keys are via
the key-directory statement.

> -- 
> Mark Andrews, ISC
> 1 Seymour St., Dundas Valley, NSW 2117, Australia
> PHONE: +61 2 9871 4742                 INTERNET: [email protected]
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [email protected]
_______________________________________________
bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to