RE: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-19 Thread LeBlanc, Daniel James
Hi Mark. The changes you recommended worked - once I removed the update-policy local / allow-update statements, named started up with only a single complaint. I have not created any DNSSEC keyfiles yet and I suspect that it why I am seeing the following: - named creates the following

RE: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-19 Thread LeBlanc, Daniel James
Hi Alan. Thanks for your detailed response. I am not quite at the point where I have reviewed everything required to roll the keys. However, you have brought to light the challenge that I will have with rolling the keys properly if I am signing on multiple auth DNS servers simultaneously. Yo