Re: rndc reload has no effect?

2011-12-31 Thread Carsten Strotmann (private)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/31/11 8:09 AM, Ken Peng wrote: Today I setup a new name system, BIND 9.7.3 with multi-views, zone transfer are going based on different TSIG-Keys. I have found a strange problem that when I edited the zone file, anded a record, increased

Take your DNSSEC with a grain of salt ...

2011-12-31 Thread Carsten Strotmann (private)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, because it was a recurring question in the ISC/Men Mice DNSSEC trainings this year, I've taken some time to write down my knowledge on NSEC3 use of the salt and iteration parameters:

RE: Take your DNSSEC with a grain of salt ...

2011-12-31 Thread Spain, Dr. Jeffry A.
I've taken some time to write down my knowledge on NSEC3 use of the salt and iteration parameters: http://strotmann.de/roller/dnsworkshop/entry/take_your_dnssec_with_a Thanks, Carsten. This is a very clear, concise, and informative article. Given the recommendation to change NSEC3 salt