Libor Peltan via knot-dns-users <[email protected]> wrote:

>> #) if I do host a given number of zone files, and

> Unfortunately, this feature has a limitation that the given number of 
> (forward) zones must be only 1 (for each reverse zone). But we might be 
> working on relaxing this limitation for future versions of Knot.

Looks like 3.4.6 is already capable of relaxing this limitation ;-)

>> But what about KSK for my reverse zone and DNSKEY "upload to the registrar"?
>> I do have the feeling I am missing an important part here ;-)

> Uploading your KSKs to your registrar is out of scope for us (unless the 
> registry supports RFC 7344), because every registrar has this different. But 
> the process is equivalent for normal and reverse zones.

My registrar doesn't provide a way to upload KSKs, and their own reverse zone 
isn't secured either. 

Thus I have to stick with an unsecured ip6.arpa reverse zone for the time being.

Thanks for your help and regards,
Michael

--

Reply via email to