Hi,
The default BIND9 installation for CentOS7 has dnssec-validation set to "yes" 
and it also includes managed-keys as well. Do those managed-keys get updated 
automatically? It is not clear from reading 
https://ftp.isc.org/isc/dnssec-guide/html/dnssec-guide.html#dnssec-validation-explained
 that these managed-keys will get updated automatically if dnssec-validation is 
not set to "auto".
[root@centos-linux ~]# named -vBIND 9.9.4-RedHat-9.9.4-73.el7_6 (Extended 
Support Version)[root@centos-linux ~]# grep named.root.key 
/etc/named.confinclude "/etc/named.root.key";[root@centos-linux ~]# cat 
/etc/named.root.keymanaged-keys {        # ROOT KEYS: See 
https://data.iana.org/root-anchors/root-anchors.xml        # for current trust 
anchor information.        #        # This key (19036) is to be phased out 
starting in 2017. It will        # remain in the root zone for some time after 
its successor key        # has been added. It will remain this file until it is 
removed from        # the root zone.        . initial-key 257 3 8 
"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF 
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX 
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD 
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz 
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS 
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=";
        # This key (20326) is to be published in the root zone in 2017.        
# Servers which were already using the old key should roll to the        # new 
# one seamlessly.  Servers being set up for the first time        # can use 
either of the keys in this file to verify the root keys        # for the first 
time; thereafter the keys in the zone will be        # trusted and maintained 
automatically.        . initial-key 257 3 8 
"AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3 
+/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv 
ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF 
0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e 
oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd 
RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN R1AkUTV74bU=";};

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to