Re: DNSEC and Bin 9.12

2019-01-29 Thread @lbutlr
On 21 Jan 2019, at 12:32, @lbutlr wrote: > A couple of questions I’d like to thank everyone who helped out on this, got it all sorted, added to the registrar, and it is all working, Now to do it for all the other domains. :) -- The most perfidious way of harming a cause consists of defending

Re: DNSEC and Bin 9.12

2019-01-26 Thread @lbutlr
On 26 Jan 2019, at 12:55, Alan Clegg wrote: > With the appropriate trust anchors in place, data in the zone validates. Everything appears to be working locally at this point, including with "auto-dnssec maintain;" which I swear was not working a few hours ago. Perhaps I tyoped. > Does this hel

Re: DNSEC and Bin 9.12

2019-01-26 Thread Alan Clegg
On 1/26/19 2:30 PM, @lbutlr wrote: > On 26 Jan 2019, at 12:20, @lbutlr wrote: >> I then removed "auto-dnssec maintain" and "inline-signing yes" from the zone >> record in name.conf and now everything is behaving as expected when I query >> localhost for the DNSSEC info. > > I should have said,

Re: DNSEC and Bin 9.12

2019-01-26 Thread @lbutlr
On 26 Jan 2019, at 12:20, @lbutlr wrote: > I then removed "auto-dnssec maintain" and "inline-signing yes" from the zone > record in name.conf and now everything is behaving as expected when I query > localhost for the DNSSEC info. I should have said, I have update-policy local; in the zone reco

Re: DNSEC and Bin 9.12

2019-01-26 Thread @lbutlr
On 21 Jan 2019, at 13:49, Mark Andrews wrote: Thanks for the info on the first two questions. >> Third, what does “not at top of zone” mean in dnssec-verify? > > Some record that should have been at the zone’s apex (name) wasn’t. Either > you passed the wrong > zone name to dnssec-verify or y

Re: DNSEC and Bin 9.12

2019-01-21 Thread Mark Andrews
> On 22 Jan 2019, at 6:32 am, @lbutlr wrote: > > A couple of questions > > First, guides on setting up DNSSEC say to add dnssec-lookaside auto; in the > options, but bind repots an error: > > /usr/local/etc/namedb/named.conf:35: dnssec-lookaside 'auto' is no longer > supported > > Does thi

DNSEC and Bin 9.12

2019-01-21 Thread @lbutlr
A couple of questions First, guides on setting up DNSSEC say to add dnssec-lookaside auto; in the options, but bind repots an error: /usr/local/etc/namedb/named.conf:35: dnssec-lookaside 'auto' is no longer supported Does this mean the entire declaration is not supported, or that auto should