This may be obvious to everyone else, and it may be documented somewhere in large letters with circles and arrows, but it was a surprise to me.
key-directory in named.conf refers to the location for the .private key files, the .key files need to go with the domain conf files. (At least if there is a way around this, it alluded me). Also, though this is more obvious, make sure you set the owner to bind for akk the key files, as when you create them they will almost certainly be owned by root. -- U is for UNA who slipped down a drain V is for VICTOR squashed by a train _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users