On 8/27/2010 11:42 AM, CT wrote:

> Per my isc class and the book I received by Jeremy C. Reid ..
> you still need to "include" your keys in the zone file either
> 
> via
> $include <dir>/KSK
> $include <dir>/ZSK1
> $include <dir>/ZSK2
> or
> (cat *.key > allkeys) which is what I have done..
> $include <dir>/allkeys
> 
> I thought the use of -S (smart signing) that this was no longer
> necessary ..?

If you use "-S", dnssec-signzone pulls the keys into the zone file based
on the timing metadata.  You don't need to $INCLUDE the keys any longer.

AlanC

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to