dnssec automatic signing

2014-08-28 Thread Jittinan Suwanruengsri
Hi, This is example.com zone $ORIGIN . $TTL 86400 ; 1 day example.com 86400 IN SOA ns.example.com. hostmaster.example.com. ( 2013122402 ; serial 86400 ; refresh (1 day) 7200

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
The next node to be signed is based on RRSIG expire times. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit

RE: dnssec automatic signing

2014-08-28 Thread Jittinan Suwanruengsri
: Re: dnssec automatic signing The next node to be signed is based on RRSIG expire times. -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ Please visit https

Re: dnssec automatic signing

2014-08-28 Thread Mark Andrews
In message 102153bef555e7489ca5d54165c431a30139d...@exchbsi02.ttt.co.th, Jit tinan Suwanruengsri writes: Hi Mark If there are many RRSIGs expire at the same time, Which record will be chosen? Any of them. It does not matter. Named just uses it as a triggering record. Sincerely,