9.9.0rc1: example from arm 4.8.3 does not validate
Spain, Dr. Jeffry A.
spainj at countryday.net
Wed Jan 18 22:55:21 UTC 2012
> I tried the example from page 23 with a local zone, a trusted key and inline-signing, ...
> But I'm getting no ad-flag
I think that is expected behavior when you query an authoritative server directly. For example, our authoritative server:
dig @ns1.countryday.net countryday.net dnskey +dnssec
also returns no ad flag, but if you run the same query from a DNSSEC-enabled recursive resolver, you will get an ad flag.
Regards, Jeff
Jeffry A. Spain
Network Administrator
Cincinnati Country Day School
More information about the bind-users
mailing list