DNSSEC

Tony Finch dot at dotat.at
Fri May 11 13:28:17 UTC 2012


WBrown at e1b.org <WBrown at e1b.org> wrote:
>
> So how do we implement one?  Create a separate caching server with DNSSEC
> validation turned off and forward all queries for the broken domain to it?

That won't work, because a validating server validates replies from a
forwarding server.

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  http://dotat.at/
FitzRoy: Northeasterly 5 to 7, occasionally gale 8 in southeast. Moderate or
rough, becoming very rough in southeast. Occasional rain. Moderate or good,
occasionally poor.



More information about the bind-users mailing list