injecting records into transfered zone (hidden primary/inline DNSSEC)

2014-10-16 Thread Thomas Goldberg
Hello, we're using bind 9.9 as authoritative DNS servers for some locally managed zones and some windows 2008 R2 active directory DNS zones (hidden primary). Now we would like to enable DNSSEC (inline signing by bind) for the windows zones. Unfortunately we came across a small problem with this

Re: injecting records into transfered zone (hidden primary/inline DNSSEC)

2014-10-16 Thread Tony Finch
Thomas Goldberg t.goldber...@gmail.com wrote: Essentially we're looking for a way to inject DS records into a slave zone (transfered from another DNS server). One way to do this is with my nsdiff script which was written to do a similar job to inline-signing mode for older versions of BIND.