Re: DS queries on parents vs. correct behaviour in answering

2010-12-04 Thread Mark Andrews
In message 02d001cb93f5$513ca2b0$f3b5e8...@janssen@eurid.eu, Peter Janssen writes: When a validating resolver queries the parent of a zone for the DS record(s), and the (child) zone is NOT signed, the response contains no answer but it does contain NSEC (NSEC3) record(s) in the authority

Re: DS queries on parents vs. correct behaviour in answering

2010-12-04 Thread Mark Andrews
Mark Andrews writes: In message 02d001cb93f5$513ca2b0$f3b5e8...@janssen@eurid.eu, Peter Janssen writes: When a validating resolver queries the parent of a zone for the DS record(s), and the (child) zone is NOT signed, the response contains no answer but it does contain NSEC

Re: bind9 cache

2010-12-04 Thread Mark Andrews
In message 20101204170822.94482eupddwii...@www.jersore.net, Benny Pedersen wr ites: i like to have bind cache in 43200 secs for any zone and update only if soa changes in that time, how do i configure named.conf to do this ? You can set a maximum bound on how long named will cache records