Converting an inline-signed zone to unsigned

Graham Clinch g.clinch at lancaster.ac.uk
Thu Mar 6 21:16:07 UTC 2014


Hi Chris & co,

> Using 9.9.5, I get messages exactly like that
> when updating the unsigned zone file while there are no keys.

Thanks for the confirmation - I've logged bind9 bug #35502 
"inline-signed zone, with no keys, does not synchronise changes made in 
master file".

Back on topic - I didn't investigate very thoroughly, but simply 
removing 'inline-signing yes' seemed to do ok for me (without marking 
the keys as deleted, or setting 'dnssec-secure-to-insecure').

Graham




More information about the bind-users mailing list