Sorry to self-reply…
I’m still getting used to dnssec-policy. With the RRSIGs directly in the zone
file now I was having some trouble. I think I got it now - I needed to change
the TTL on a given RR, and delete the RRSIG for that RR. Lather, rinse, repeat
for any/all other RR’s. BIND will
Hello,
I changed one of my domains over to dnssec-policy today (in a “nuclear”
fashion) - but everything went surprisingly well. Previous to this, I had
lowered all my TTLs to hopefully help with this process or any errors/mistakes
I might make.
I then went to put the TTLs back to their
2 matches
Mail list logo