As a result, they report warnings such as:

those tools are broken.

Is this independent signed serial expected behavior for BIND 9.18.39 with 
dnssec-policy and inline-signing?

Yes.

Is there any supported configuration that preserves the source SOA serial in 
the served signed zone while still allowing automatic signing and automatic key 
maintenance?

No, and that is not possible. Consider a zone which is not updates: RRSIGs need 
to be periodically refreshed which causes the SOA serial to increase so that 
NOTIFY / XFR to/from secondaries works.

dnssec-policy currently knows: serial-update-method ( date | increment | unixtime ), with 
"date" creating a YYYYMMDDnn format (with nn between 00 and 99 and more than 100 updates 
per day rolling over onto "tomorrow".

If not, would ISC consider adding an optional configuration (for example, a 
policy or zone option) that allows the served signed zone to retain the source 
SOA serial where administrators intentionally use YYYYMMDDNN serial numbering?

I am not affiliated with ISC, but I doubt they would, because of the previous 
answer.

        -JP
--
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
this list.

Reply via email to