dnssec automatic signing

2014-08-28 Thread Jittinan Suwanruengsri
Hi, This is example.com zone $ORIGIN . $TTL 86400 ; 1 day example.com 86400 IN SOA ns.example.com. hostmaster.example.com. ( 2013122402 ; serial 86400 ; refresh (1 day) 7200

To DLV or not to DLV [was Re: recursive lookups for UNSECURE names ...]

2014-08-28 Thread Chris Thompson
On Aug 28 2014, Doug Barton wrote: On 8/27/14 3:03 PM, Timothe Litt wrote: So you really meant that validating resolvers should only consult DLV if their administrator knows that users are looking-up names that are in the DLV? That's how I read your advice. You're correct. I don't see how

Re: recursive lookups for UNSECURE names fail if dlv.isc.org is unreachable and dnssec-lookaside is 'auto'

2014-08-28 Thread Timothe Litt
On 27-Aug-14 20:35, Doug Barton wrote: On 8/27/14 3:03 PM, Timothe Litt wrote: So you really meant that validating resolvers should only consult DLV if their administrator knows that users are looking-up names that are in the DLV? That's how I read your advice. You're correct. I don't see

Re: recursive lookups for UNSECURE names fail if dlv.isc.org is unreachable and dnssec-lookaside is 'auto'

2014-08-28 Thread Doug Barton
On 8/28/14 10:55 AM, Timothe Litt wrote: Aside from the use of the word 'absurdity', I'm not offended. I am trying to educate. And while I recognize that I'm arguing pragmatism with a market purist, It's nice to be called pure, in some context anyway. :) However as I pointed out I'm not

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
The next node to be signed is based on RRSIG expire times. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit

RE: dnssec automatic signing

2014-08-28 Thread Jittinan Suwanruengsri
Hi Mark If there are many RRSIGs expire at the same time, Which record will be chosen? Sincerely, Mr.Jittinan Suwanrueangsri -Original Message- From: Mark Andrews [mailto:ma...@isc.org] Sent: Friday, August 29, 2014 5:36 AM To: Jittinan Suwanruengsri Cc: bind-us...@isc.org Subject:

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
In message 102153bef555e7489ca5d54165c431a30139d...@exchbsi02.ttt.co.th, Jit tinan Suwanruengsri writes: Hi Mark If there are many RRSIGs expire at the same time, Which record will be chosen? Any of them. It does not matter. Named just uses it as a triggering record. Sincerely,