> Doug Barton <mailto:do...@dougbarton.us> > Monday, November 17, 2014 2:16 PM > > > That seems like something that should be fixable in BIND, yes? (And > thanks for doing that testing, btw) > it's not broken. dnssec has no facility for validating data at slave synchronization time (after each axfr or ixfr or rsync). this isn't a bind-ism. validation is defined to happen at consumption time.
-- Paul Vixie
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop