Re: Unable to get authenticated negative responses from BIND 9.6.0 w/ NSEC3?

2009-01-13 Thread Johan Ihren
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Mark, Anyone done this recently who can give me a suggestion to where I may go wrong? NXDOMAIN + OPTOUT - AD=0 Doh! I reversed the logic for OPTOUT in my apparently confused head. Many thanks for the quick correction. Everything

Re: Unable to get authenticated negative responses from BIND 9.6.0 w/ NSEC3?

2009-01-12 Thread Mark Andrews
In message a0e00a9b-89cc-4b94-a3a5-49fd22fe3...@johani.org, Johan Ihren writes: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I realise this just has to be a user error, but sofar I've been completely unsuccessful in getting an authenticated response from a 9.6.0 recursive server with

Re: Unable to get authenticated negative responses from BIND 9.6.0 w/ NSEC3?

2009-01-12 Thread Johan Ihren
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Mark, On 12 Jan 2009, at 23:49, Mark Andrews wrote: I realise this just has to be a user error, but sofar I've been completely unsuccessful in getting an authenticated response from a 9.6.0 recursive server with trusted keys correctly

Re: Unable to get authenticated negative responses from BIND 9.6.0 w/ NSEC3?

2009-01-12 Thread Mark Andrews
In message 088512ac-625e-4a72-aa90-65c73fb8b...@johani.org, Johan Ihren writes: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Mark, On 12 Jan 2009, at 23:49, Mark Andrews wrote: I realise this just has to be a user error, but sofar I've been completely unsuccessful in getting an

Unable to get authenticated negative responses from BIND 9.6.0 w/ NSEC3?

2009-01-11 Thread Johan Ihren
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I realise this just has to be a user error, but sofar I've been completely unsuccessful in getting an authenticated response from a 9.6.0 recursive server with trusted keys correctly configured. I've done this: * Signed the zones: parent is