RE: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-19 Thread LeBlanc, Daniel James
[mailto:bind-users-boun...@lists.isc.org] On Behalf Of Alan Clegg Sent: March-18-19 9:12 PM To: bind-users@lists.isc.org Subject: Re: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing On 3/18/19 7:33 PM, LeBlanc, Daniel James wrote: > I have a pair of ISC BIND 9.12.3-P1 servers that are configu

RE: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-19 Thread LeBlanc, Daniel James
iel James Cc: bind-users@lists.isc.org Subject: Re: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing > On 19 Mar 2019, at 10:59 am, LeBlanc, Daniel James > wrote: > > Thanks Mark for your quick response. > > On page 29 of the Bv9-12-3-P1ARM I had seen the following, which

Re: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-18 Thread Mark Andrews
; Thanks again! > > Daniel J. LeBlanc, P.Eng., MBA, DTME | Senior Network Architect | Bell Canada > > -Original Message- > From: Mark Andrews [mailto:ma...@isc.org] > Sent: March-18-19 8:40 PM > To: LeBlanc, Daniel James > Cc: bind-users@lists.isc.org > Subject: Re: IS

Re: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-18 Thread Alan Clegg
On 3/18/19 7:33 PM, LeBlanc, Daniel James wrote: > I have a pair of ISC BIND 9.12.3-P1 servers that are configured as > slaves to a pair of Hidden Master servers.  The Hidden Masters are a > proprietary product and unfortunately when used to sign the zones, the > SOA records are not populated as

RE: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-18 Thread LeBlanc, Daniel James
I will try this out in the morning. Thanks again! Daniel J. LeBlanc, P.Eng., MBA, DTME | Senior Network Architect | Bell Canada -Original Message- From: Mark Andrews [mailto:ma...@isc.org] Sent: March-18-19 8:40 PM To: LeBlanc, Daniel James Cc: bind-users@lists.isc.org Subject: Re: ISC BIND 9.12.3-P1

Re: ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-18 Thread Mark Andrews
You don’t need update-policy local. In inline-signing mode named maintains its own copy of the zone with the DNSSEC records in addition to the copy from upstream. DNSSEC is controlled by rndc. > On 19 Mar 2019, at 10:33 am, LeBlanc, Daniel James > wrote: > > Hello All. > > I have a pair

ISC BIND 9.12.3-P1 Question re: DNSSEC Zone Signing

2019-03-18 Thread LeBlanc, Daniel James
Hello All. I have a pair of ISC BIND 9.12.3-P1 servers that are configured as slaves to a pair of Hidden Master servers. The Hidden Masters are a proprietary product and unfortunately when used to sign the zones, the SOA records are not populated as expected. As a result, I was looking into