On Nov 28, 2014, at 02:07 , Paul Vixie <[email protected]> wrote: > > is there some reason why an updated sig(0) is not a solution to this?
People move zone data around using mechanisms other than *XFR (scp, database replication, etc.). A signature on the complete zone, as part of the zone, also covers those mechanisms. _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs
