In message <500978a5.4070...@imperial.ac.uk>, Phil Mayers writes:
> On 20/07/12 16:21, Mark Andrews wrote:
> >
> > In message <50096c2b.1080...@interlinx.bc.ca>, "Brian J. Murrell" writes:
> >> Just for good measure, since I think I have posted this before, but here
> >> are the options I have set in my bind configuration with regard to dnssec=
> >> :
> >>
> >>          dnssec-enable yes;
> >>          dnssec-validation yes;
> >>          dnssec-lookaside auto;
> 
> FWIW, on 9.8 the only other line we have (for reasons of permissions) is:
> 
>    managed-keys-directory "/var/named/data/dynamic";
> 
> I don't see why those 3 lines aren't sufficient for him?
> 
> >
> > Turn on validation using the root's DNSKEY.
> >
> >     auto-dnssec maintian;
> 
> I thought that was for master zones, not recursion/validation? Or am I 
> missing something?

        My bad.  "dnssec-validation auto;" is what I was thinking about.

> _______________________________________________
> Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe
>  from this list
> 
> bind-users mailing list
> bind-users@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: ma...@isc.org
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to