On 5/26/20 4:50 PM, Mark Andrews wrote: > This is where we need to get the registrars to follow standards. They are > written > so everyone doesn’t have to cobble together ad-hoc solutions. Hourly scans > of all > the DNSSEC delegations by the registrars would do. > > push solutions
sounds reasonable. at very least, better than nothing. in the absence of a standards-based solution, any options for hooks in bind to external scripts, even if ad-hoc? e.g., "if when change in DS Record in local bind, then fire this external script which will manage the DS submit/withdraw via API to registrar" a completely de-coupled solution, independent of bind itself, is doable -- but again, ad-hoc, and seems a step backwards given the nice progress with dnssec-policy/kasp simplifications in recent versions. if that's all there is, know of any existing, proven ad-hoc solutions? _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users