On lun. 31 juil. 11:00:38 2017, Daniel Stirnimann wrote: > Hello Xavier, > > Your question is a bit unclear to me. > > Where do you have a problem? > a) Finding your KSK for your zone? > b) Finding the DNSKEY text box on the Gandi website? > > Answer to a): > > knotc zone-read <domain> <domain> DNSKEY > > Answer to b): > > I'm a Gandi customer myself. Gandi requires the DNSKEY (not the DS > record). Note also that Gandi does not support DNSSEC for all TLDs. This > is indicated in the Gandi user interface when managing a domain.
Thanks for you feedbacks :) I’ve update my article with the `knotc zone-read` command. https://www.swordarmor.fr/gestion-automatique-de-dnssec-avec-knot.html#publication-dnskey-nouvelle-methode -- alarig
signature.asc
Description: PGP signature
_______________________________________________ knot-dns-users mailing list knot-dns-users@lists.nic.cz https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users