[BUG] dnssec-signzone silently drops DS records when '-g' is used

Ondřej Surý ondrej.sury at nic.cz
Tue Sep 16 10:02:12 UTC 2008


Hi Mark,
2008/9/16 Mark Andrews <Mark_Andrews at isc.org>:
>
> In message <e90946380809151121k9afb519jabda6a291c1bd69a at mail.gmail.com>, "=?UTF
> -8?Q?Ond=C5=99ej_Sur=C3=BD?=" writes:
>> Hi,
>> I just found quite serious bug in dnssec-signzone :-(.
>
>        It's not a bug.  It was a deliberate decision to only include
>        generate DS records when -g is specified.  You manage the
>        transition from secure to insecure by removing the keyset
>        of the child.

Ok, it's just documentation bug.  I made some suggestions how to improve
man page and -h output in #18635.

Ondrej.
-- 
 Ondřej Surý
 technický ředitel/Chief Technical Officer
 -----------------------------------------
 CZ.NIC, z.s.p.o. -- .cz domain registry
 Americká 23,120 00 Praha 2,Czech Republic
 mailto:ondrej.sury at nic.cz http://nic.cz/
 sip:ondrej.sury at nic.cz tel:+420.222745110
 mob:+420.739013699 fax:+420.222745112
 -----------------------------------------


More information about the bind-users mailing list