Shawn Zhou via bind-users <bind-users@lists.isc.org> wrote: > Thanks Even. Sounds like "dnssec-validation auto" is a more > future-proof option for what want it. I will use that instead.
My recommendation is to avoid configuring or installing root trust anchors, and let named handle all that itself. In BIND 9.14 and later you don't need any configuration for working DNSSEC validation :-) Tony. -- f.anthony.n.finch <d...@dotat.at> http://dotat.at/ Forties, Cromarty, Forth: Cyclonic 5 to 7, occasionally gale 8 at first in Forth, becoming south or southeast 5 or 6 later. Moderate or rough. Rain, fog patches except in Forth. Moderate, occasionally very poor except in Forth. _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users