Krzysztof Olesik kolesik at gmail.com
Fri Sep 15 13:02:11 UTC 2006


I have just tested the use of dnssec along with dynamic updates on bind
9.3.2. Everything works fine but I have noticed interesting thing.
Namely, when I added a glue record to a zone, by means of nsupdate
tool, a RRSIG for the glue record appeared in the zone. AFAIK, dnssec
specification says that only authoritative data is signed.

Could you explain this behaviour?

May the presence of this additional RRSIG spoil something in DNS?

Krzysztof Olesik

More information about the bind-users mailing list