Re: Providing AD flag for authoritative domains

2022-12-24 Thread Nick Tait via bind-users
On 23/12/2022 2:30 am, Jesus Cea wrote: Is there any way to configure bind to verify DNSSEC integrity and signal the AD flag for authoritative domains?. Views (it would lose the AA flag, then)? What would be the best practice for dnssec verification? To use a fully validating local resolver?

Re: Providing AD flag for authoritative domains

2022-12-22 Thread Mark Andrews
> On 23 Dec 2022, at 01:13, Emmanuel Fusté wrote: > > Le 22/12/2022 à 14:30, Jesus Cea a écrit : >> I have a validating DNSSEC bind server. I get AD (Authenticated Data) flag >> when requesting details from a DNSSEC protected domain. Good. >> >> The point is that when the requested DNS name

Re: Providing AD flag for authoritative domains

2022-12-22 Thread Emmanuel Fusté
Le 22/12/2022 à 14:30, Jesus Cea a écrit : I have a validating DNSSEC bind server. I get AD (Authenticated Data) flag when requesting details from a DNSSEC protected domain. Good. The point is that when the requested DNS name belongs to a domain with this server is authoritative and that

Re: Providing AD flag for authoritative domains

2022-12-22 Thread Ray Bellis
On 22/12/2022 13:30, Jesus Cea wrote: I have a validating DNSSEC bind server. I get AD (Authenticated Data) flag when requesting details from a DNSSEC protected domain. Good. The point is that when the requested DNS name belongs to a domain with this server is authoritative and that domain