[BUG] dnssec-signzone silently drops DS records when '-g' is used
Ondřej Surý
ondrej.sury at nic.cz
Tue Sep 16 10:02:12 UTC 2008
Hi Mark,
2008/9/16 Mark Andrews <Mark_Andrews at isc.org>:
>
> In message <e90946380809151121k9afb519jabda6a291c1bd69a at mail.gmail.com>, "=?UTF
> -8?Q?Ond=C5=99ej_Sur=C3=BD?=" writes:
>> Hi,
>> I just found quite serious bug in dnssec-signzone :-(.
>
> It's not a bug. It was a deliberate decision to only include
> generate DS records when -g is specified. You manage the
> transition from secure to insecure by removing the keyset
> of the child.
Ok, it's just documentation bug. I made some suggestions how to improve
man page and -h output in #18635.
Ondrej.
--
Ondřej Surý
technický ředitel/Chief Technical Officer
-----------------------------------------
CZ.NIC, z.s.p.o. -- .cz domain registry
Americká 23,120 00 Praha 2,Czech Republic
mailto:ondrej.sury at nic.cz http://nic.cz/
sip:ondrej.sury at nic.cz tel:+420.222745110
mob:+420.739013699 fax:+420.222745112
-----------------------------------------
More information about the bind-users
mailing list