Suggestions for a distributed DNS zone hosting solution I'm designing

2018-03-06 Thread Latitude
I would like to solicit constructive feedback in regards to a distributed DNS zone hosting proof of concept I'd like to design and establish. I must deploy a DNS system with the following requirements: - single master server, multiple slave servers - minimal time for name resolving for Americas,

Re: DNSSEC and nsupdate

2018-03-06 Thread Mark Andrews
> On 7 Mar 2018, at 3:48 am, Tony Finch wrote: > > Prof. Dr. Michael Schefczyk wrote: >> >> The issue is that normal permissions in the key-directory are root:bind >> 0644 for the public key and root:bind 0600 for the private key. The >> issue disappears when setting the private key to 0644 al

Re: AW: DNSSEC and nsupdate

2018-03-06 Thread Tony Finch
Prof. Dr. Michael Schefczyk wrote: > > The issue is that normal permissions in the key-directory are root:bind > 0644 for the public key and root:bind 0600 for the private key. The > issue disappears when setting the private key to 0644 also and that must > be done before starting bind - before us