>> the 'inline-signing yes;' is needed IN ADDITION to 'dnssec-policy' in order to >> _not_ overwrite original zone files/data on signing. > > I cannot confirm that (9.17.22): sry, fat thumbed copying my reply into email :-/ should have been wrapped in niceties, including "hmm, I can here with 9.18.8 ..."