Re: Piggybacking on a zone’s dnssec-policy using auto-dnssec: How can one do this after Bind 9.19?

2023-04-17 Thread Matthijs Mekking
Hi Andrej, While I am not 100% sure on your use case, let me at least respond to this: > But I’m starting to realize that I had misunderstood and > overcomplicated things; simply referencing the "standard" policy again > from equivalent zones in different views should (?) magically work (as > Ni

Re: Piggybacking on a zone’s dnssec-policy using auto-dnssec: How can one do this after Bind 9.19?

2023-04-17 Thread Andrej Podzimek via bind-users
Hi Matthijs, Thanks for your response.   dnssec-policy "ReuseKeysFromTheMainView" {     keys {       ksk key-directory lifetime unlimited algorithm ecdsap384sha384;       zsk key-directory lifetime unlimited algorithm ;     };     nsec3param s

Re: Piggybacking on a zone’s dnssec-policy using auto-dnssec: How can one do this after Bind 9.19?

2023-04-17 Thread Nick Tait via bind-users
On 17/04/23 09:08, Andrej Podzimek via bind-users wrote: The easiest (?) way to make DNSSEC work in all views has been to keep a dnssec-policy for zones in *one* of the views (to generate and maintain keys) and then passively refer to the keys from the zones’ counterparts in other views using a

Re: Piggybacking on a zone’s dnssec-policy using auto-dnssec: How can one do this after Bind 9.19?

2023-04-17 Thread Matthijs Mekking
Hello Andrej, On 4/16/23 23:08, Andrej Podzimek via bind-users wrote: Hi bind-users, I have asked this question on GitLab, but hijacking a closed issue to ask questions is bad practice (often rewarded with silence), so I’m re-posting the question here. https://gitlab.isc.org/isc-projects/bin

Piggybacking on a zone’s dnssec-policy using auto-dnssec: How can one do this after Bind 9.19?

2023-04-16 Thread Andrej Podzimek via bind-users
Hi bind-users, I have asked this question on GitLab, but hijacking a closed issue to ask questions is bad practice (often rewarded with silence), so I’m re-posting the question here. https://gitlab.isc.org/isc-projects/bind9/-/issues/3769#note_356577 My DNS server serves multiple views that s