NSEC3/NSEC transition
David Sherman
dsherman at bluecatnetworks.com
Thu Feb 14 23:11:30 UTC 2013
Thank you Mark
Regards,
David
-----Original Message-----
From: Mark Andrews [mailto:marka at isc.org]
Sent: February-14-13 5:39 PM
To: David Sherman
Cc: bind-users at isc.org
Subject: Re: NSEC3/NSEC transition
In message <CB52CF69EC353F4FBC9BA1581123C72E1C73DF62 at TORMBXW01.bluecatnetworks.
corp>, David Sherman writes:
> Thank you, Mark
>
> Is it safe to keep -u option for dnssec-signzone in all cases,
> regardless o= f current actual NSEC/NSEC3 chains.
>
> Thanks,
> David
I had forgotten about "-u". Being a appliance vendor you may want to use it all the time as you have a dashboards etc.
For individuals that are just re-signing a zone, I would say no.
Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: marka at isc.org
More information about the bind-users
mailing list