forwarding zone setup from a BIND slave (without recursion?)

2021-04-06 Thread RK K
All, We have a set of BIND primary servers (MASTERs) and a set of secondary servers (slaves to the MASTERs). The secondary BIND DNS servers disabled recursion ( with "*recursion no;" *) in the global options. All the applications/systems do use secondary DNS servers for name resolution. Now there

Re: Still seeing some ALG-7 DNSSE

2021-04-06 Thread Matthijs Mekking
Most likely you have to delete those files manually. In 9.16.13, a new "dnssec-policy" option is introduced, "purge-keys". By default the keys are retained for 90 days after their latest usage. So in that case keys will be cleaned up automatically. If you run a lower version, or if you set "p