Hi,

I'm using OpenDNSSEC 1.3.2. I'm trying to set a very low TTL (like 60)
for one label in the zone (the IP address is going to change and I want
to minimize downtime). I noticed, that in the signed file, all TTLs are
clamped to the SOA minimum value set in KASP. When I lowered that value,
all RRSIG and NSEC3 records in the zone were set to this lowest TTL.

Is it somehow possible to lower TTL of only one label (and probably the
nearest neighbours in the NSEC3 chain) without affecting all the
signatures in the zone?

Ragards,

Ondřej Caletka,
CESNET

Attachment: smime.p7s
Description: Elektronicky podpis S/MIME

_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to