Re: OpenDNS today announced it has adopted DNSCurve to secure DNS

2010-02-25 Thread Eugene Crosser
Joe Baptista wrote: > ORG and GOV and quite a lot of the ccTLD's are "DNSSEC compatible", so I > don't actually think it'd be much of a horserace if compatibility is all > you're looking for. > > > I agree they are both DNSSEC compatible but .GOV has only deployed > DNSSEC in 20% of

Automatic key rollover (Was: DNSSEC: Configuring auto-signed dynamic zones HOWTO)

2010-02-23 Thread Eugene Crosser
Nicholas Wheeler wrote: > On Tue, 2010-02-23 at 23:40 +0300, Eugene Crosser wrote: >> (Well, for now the plan is to do it once a year by hand. Then, we'll see...) > > For the record, NIST recommends to roll the ZSK every three months, and > the KSK every two years. Let

Re: DNSSEC: Configuring auto-signed dynamic zone HOWTO

2010-02-23 Thread Eugene Crosser
Stephane Bortzmeyer wrote: > There is nothing about key rollover, it seems? How do you handle it? I don't. (Well, for now the plan is to do it once a year by hand. Then, we'll see...) Regards, Eugene signature.asc Description: OpenPGP digital signature __

Re: [SPAM:5.2] Re: Installing 9.7?

2010-02-22 Thread Eugene Crosser
Daniel Morgan wrote: > On Mon, 2010-02-22 at 08:00 +, Evan Hunt wrote: >>> This completed just fine - but what I can't find is any details on how >>> to physically install it after building. I'm used to things like 'make >>> install', but I don't want to blindly run random commands that may cau

Re: DNSSEC: Configuring auto-signed dynamic zone HOWTO

2010-02-22 Thread Eugene Crosser
> HOW TO CONFIGURE AUTO-SIGNED DYNAMIC ZONES WITH BIND9 > > This document describes how to configure bind9 to > automatically sign zones as they are being modified > by dynamic update mechanism. Reviewed version placed here: http://www.average.org/dnssec/ Eugene

DNSSEC: Configuring auto-signed dynamic zone HOWTO

2010-02-18 Thread Eugene Crosser
Please comment! Eugene === HOW TO CONFIGURE AUTO-SIGNED DYNAMIC ZONES WITH BIND9 This document describes how to configure bind9 to automatically sign zones as they are being modified by dynamic update mechanism. It is assumed that you already know how

Re: DNSSEC: Configuring auto-signed dynamic zone

2010-02-16 Thread Eugene Crosser
Mark Andrews wrote: >> I would like to make dynamic zone automatically signed. > Firstly upgrade to BIND 9.6.0 or later as it supports re-signing [etc] Thanks Mark! With your directions, I got the system airborne in no time. Do you think there is an appropriate place somewhere for a small one-

DNSSEC: Configuring auto-signed dynamic zone

2010-02-15 Thread Eugene Crosser
Hello everyone, I am new here. I am running a manually signed zone (average.org) for my domain for some time now. I also have a separate subdomain zone (dyn.average.org) that allows dynamic updates, and that is currently not signed. Bind version is 9.5.1. (debian stable). I would like to make dyn