Joe Baptista wrote:

> [....................] I guess that depends on if DNSSEC
> is turned on by default in BIND. Incidentally - is it?

   dnssec-enable yes;
and
   dnssec-validation yes;

are the defaults since BIND 9.5

Serving signed zones requires signed zone data to serve.

Validation requires configuration of trust anchors.

AlanC

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to