Re: [knot-dns-users] Correct way to turn off dnssec-signing

2018-10-18 Thread Oliver Peter
y] + [max TTL seen in zone/knot_soa_minimum] seconds until I manually remove the material. Does that sound reasonable? Thanks! -- Oliver PETER oli...@gfuzz.de 0x456D688F -- https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

[knot-dns-users] Correct way to turn off dnssec-signing

2018-10-17 Thread Oliver Peter
ot change anything; I also created a second policy called "unsign-policy" where I switched cds-cdnskey-publish to "cds-cdnskey-publish". I expected the CDNSKEY/CDS immediately turn into "0 3 0 AA==" and so on since my propagation-delay is 0 (for faster test results...) Thanks for any hints! -- Oliver PETER oli...@gfuzz.de 0x456D688F -- https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users