Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-11-10 Thread Matthijs Mekking
Since the latest release dnssec-policy requires either inline-signing to be set to yes, or allow dynamic updates. I am thinking of adding inline-signing to dnssec-policy, do you think that would that be useful? Matthijs, Yes, from my point of view, that would surely be useful. I would

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-11-09 Thread Tom
named.conf and contain them in one stanza. But some options are more difficult to be replaced than others. On 24-10-2022 18:16, PGNet Dev wrote: i've read this comment 'inline-signing' might go away and be replaced by dnssec-policy now a few times, in posts and in docs currently, WITH 'dnssec

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread PGNet Dev
' might go away and be replaced by dnssec-policy ? Retried my named.conf with BIND 9.19.7-dev (Development Release) which reports: 26-Oct-2022 21:31:42.021 /private/tmp/b/named.conf:11: 'inline-signing yes;' must also be configured explicitly for zones using dnssec-policy without a configured

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread Jan-Piet Mens via bind-users
Retried my named.conf with BIND 9.19.7-dev (Development Release) which reports: 26-Oct-2022 21:31:42.021 /private/tmp/b/named.conf:11: 'inline-signing yes;' must also be configured explicitly for zones using dnssec-policy without a configured 'allow-update' or 'update-policy'. See

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread PGNet Dev
the 'inline-signing yes;' is needed IN ADDITION to 'dnssec-policy' in order to _not_ overwrite original zone files/data on signing. I cannot confirm that (9.17.22): sry, fat thumbed copying my reply into email :-/ should have been wrapped in niceties, including "hmm, I can here with 9.18.8

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread PGNet Dev
ls -1 keys/dnssec/example.com/ (empty) ls -1 namedb/primary/example.com* namedb/primary/example.com.zone<== ORIGINAL, unsigned zone file cat etc/named.conf ... zone "example.com" IN { type master; file "namedb/primary/example.com.zone";

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread Jan-Piet Mens via bind-users
the 'inline-signing yes;' is needed IN ADDITION to 'dnssec-policy' in order to _not_ overwrite original zone files/data on signing. I cannot confirm that (9.17.22): % ls -1 example.aa named.conf % cat named.conf options { directory "."; listen-on port 5301 { 127.0.0.2; };

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread PGNet Dev
There are two ways of DNSSEC maintenance in BIND. One is the inline-signing approach, that preserves the original zone file. The other is to apply the changes directly to the zone (and zone file) and requires the zone to allow dynamic updates. Since the latest release dnssec-policy requires

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread Mark Elkins via bind-users
onfiguration options that are scattered throughout named.conf and contain them in one stanza. But some options are more difficult to be replaced than others. On 24-10-2022 18:16, PGNet Dev wrote: i've read this comment 'inline-signing' might go away and be replaced by dnssec-policy now a few times,

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread Tom
stanza. But some options are more difficult to be replaced than others. On 24-10-2022 18:16, PGNet Dev wrote: i've read this comment 'inline-signing' might go away and be replaced by dnssec-policy now a few times, in posts and in docs currently, WITH 'dnssec-policy' signing enabled & in

Re: 'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-26 Thread Matthijs Mekking
to be replaced than others. On 24-10-2022 18:16, PGNet Dev wrote: i've read this comment 'inline-signing' might go away and be replaced by dnssec-policy now a few times, in posts and in docs currently, WITH 'dnssec-policy' signing enabled & in-use, i've zone "ex

'inline-signing' might go away and be replaced by dnssec-policy ?

2022-10-24 Thread PGNet Dev
i've read this comment 'inline-signing' might go away and be replaced by dnssec-policy now a few times, in posts and in docs currently, WITH 'dnssec-policy' signing enabled & in-use, i've zone "example.com" IN { type master; file "namedb/prima