RE: Bind 9.9.x operation with dnssec

2012-06-01 Thread Spain, Dr. Jeffry A.
> With "auto-dnssec maintain", I expect the Zone Signing Keys and the > individual RRSIGs to be completely managed and rotated as needed by bind, per > https://kb.isc.org/article/AA-00626/0/Inline-Signing-in-ISC-BIND-9.9.0-Examples.html and the Admin Reference, however, at the end of 4.9.7, it sa

Re: Bind 9.9.x operation with dnssec

2012-06-01 Thread Jeremy C. Reed
On Fri, 1 Jun 2012, Alan Batie wrote: > When it comes to the DS records registered at the registrar, I'm not > sure where that comes from: the only way I can see to get it is to do a > DS query from the nameserver (and at least one document basically said > that). First, I'd like to know where it

Bind 9.9.x operation with dnssec

2012-06-01 Thread Alan Batie
I'm a little confused wading through the massive amount of detail about dnssec, and have two main questions: 1. General key management 2. Specific problems with my test domain setup (raindrop.us) For general key management: With "auto-dnssec maintain", I expect the Zone Signing Keys and the in