On lun. 31 juil. 11:00:38 2017, Daniel Stirnimann wrote:
> Hello Xavier,
> 
> Your question is a bit unclear to me.
> 
> Where do you have a problem?
>  a) Finding your KSK for your zone?
>  b) Finding the DNSKEY text box on the Gandi website?
> 
> Answer to a):
> 
> knotc zone-read <domain> <domain> DNSKEY
> 
> Answer to b):
> 
> I'm a Gandi customer myself. Gandi requires the DNSKEY (not the DS
> record). Note also that Gandi does not support DNSSEC for all TLDs. This
> is indicated in the Gandi user interface when managing a domain.

Thanks for you feedbacks :) I’ve update my article with the `knotc
zone-read` command.
https://www.swordarmor.fr/gestion-automatique-de-dnssec-avec-knot.html#publication-dnskey-nouvelle-methode

-- 
alarig

Attachment: signature.asc
Description: PGP signature

_______________________________________________
knot-dns-users mailing list
knot-dns-users@lists.nic.cz
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

Reply via email to