moving DNSSEC to a hidden master

2013-10-01 Thread David Newman
Is there a recommended order of operations when moving DNSSEC-enabled nameservers to a hidden-master setup? I'm hoping it's just as simple as moving all these files into place on the hidden master: *.key *.private managed-keys.bind *.jbk *.jnl *.signed *.signed.jnl If not, what do I need to do?

Re: moving DNSSEC to a hidden master

2013-10-01 Thread Alan Clegg
On Oct 1, 2013, at 8:27 PM, David Newman dnew...@networktest.com wrote: On 10/1/13 2:16 PM, David Newman wrote: Is there a recommended order of operations when moving DNSSEC-enabled nameservers to a hidden-master setup? Actually, this is really a more general question: Is there a

Re: moving DNSSEC to a hidden master

2013-10-01 Thread Sten Carlsen
On 02/10/13 02.47, Alan Clegg wrote: On Oct 1, 2013, at 8:27 PM, David Newman dnew...@networktest.com wrote: On 10/1/13 2:16 PM, David Newman wrote: Is there a recommended order of operations when moving DNSSEC-enabled nameservers to a hidden-master setup? Actually, this is really a more

Re: moving DNSSEC to a hidden master

2013-10-01 Thread Alan Clegg
On Oct 1, 2013, at 9:04 PM, Sten Carlsen st...@s-carlsen.dk wrote: On 02/10/13 02.47, Alan Clegg wrote: On Oct 1, 2013, at 8:27 PM, David Newman dnew...@networktest.com wrote: On 10/1/13 2:16 PM, David Newman wrote: Is there a recommended order of operations when moving

Re: moving DNSSEC to a hidden master

2013-10-01 Thread Mark Andrews
As Alan said copy the .key and .private files over. Disable updating on the old master. Transfer the zone contents by setting up as a slave using masterfile-format text; or using by using dig. This will give you the most up to date version of the zone. dig axfr zone +onesoa @oldmaster