Re: DNSKEY and RRSIG DNSKEY TTL values aren't changed after changing of zone's TTL

2016-08-16 Thread Александр Остапенко
without the need of unsigning/signing cycle. Besides, the question is: this is a bug? Or this behavior is caused by some rules or restrictions? С уважением, Александр Остапенко 2016-08-16 8:59 GMT+07:00 Mark Andrews : > > In message mail.gmail.com> > , =?UTF-8?B?0JDQu9C10LrRgdCw0L3

DNSKEY and RRSIG DNSKEY TTL values aren't changed after changing of zone's TTL

2016-08-15 Thread Александр Остапенко
Hello. I'm using BIND 9.9.5. My steps: 1. Sign zone using one 1 ZSK and 2 KSK: a) adding "*auto-dnssec maintain;*" and "*inline-signing yes;*" directive into zone section of named.conf; b) setting publication and activation timestamps to current time in key files; c) *rndc reload*.