Re: error: 'allow-update' is not allowed in 'slave' zone

2024-02-14 Thread Adrian Zaugg
Hi Mounika If you connect to a secondary nameserver to accept dynamic zone updates you have to configure on the secondary inside the slave zone section a statement: allow-update-forwarding { dhcp-updates; }; ...where "dhcp-updates" is an ACL (that could be named as you

Re: migration from auto-dnssec to dnssec-policy deletes keys immediately

2023-12-28 Thread Adrian Zaugg
Hi Nick Not changing the key algo does help indeed when introducing dnssec-policy, see the log below. Thank you very much for pointing this out. But I do not understand why BIND deletes valid and published keys, just because there should be another algo used. Couldn't this be done in a smooth

migration from auto-dnssec to dnssec-policy deletes keys immediately

2023-12-27 Thread Adrian Zaugg
Dear List Trying to migrate a zone from auto-dnssec zone "myzone.ch" { key-directory "/var/lib/bind/keys"; auto-dnssec maintain; inline-signing yes; type master; [...] to dnssec-policy zone