In message <500978a5.4070...@imperial.ac.uk>, Phil Mayers writes: > On 20/07/12 16:21, Mark Andrews wrote: > > > > In message <50096c2b.1080...@interlinx.bc.ca>, "Brian J. Murrell" writes: > >> Just for good measure, since I think I have posted this before, but here > >> are the options I have set in my bind configuration with regard to dnssec= > >> : > >> > >> dnssec-enable yes; > >> dnssec-validation yes; > >> dnssec-lookaside auto; > > FWIW, on 9.8 the only other line we have (for reasons of permissions) is: > > managed-keys-directory "/var/named/data/dynamic"; > > I don't see why those 3 lines aren't sufficient for him? > > > > > Turn on validation using the root's DNSKEY. > > > > auto-dnssec maintian; > > I thought that was for master zones, not recursion/validation? Or am I > missing something?
My bad. "dnssec-validation auto;" is what I was thinking about. > _______________________________________________ > Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe > from this list > > bind-users mailing list > bind-users@lists.isc.org > https://lists.isc.org/mailman/listinfo/bind-users -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users