Hi, I'm using OpenDNSSEC 1.3.2. I'm trying to set a very low TTL (like 60) for one label in the zone (the IP address is going to change and I want to minimize downtime). I noticed, that in the signed file, all TTLs are clamped to the SOA minimum value set in KASP. When I lowered that value, all RRSIG and NSEC3 records in the zone were set to this lowest TTL.
Is it somehow possible to lower TTL of only one label (and probably the nearest neighbours in the NSEC3 chain) without affecting all the signatures in the zone? Ragards, Ondřej Caletka, CESNET
smime.p7s
Description: Elektronicky podpis S/MIME
_______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
