OpenDNS today announced it has adopted DNSCurve to secure DNS

Alan Clegg aclegg at isc.org
Thu Feb 25 03:08:27 UTC 2010


Joe Baptista wrote:

> [....................] I guess that depends on if DNSSEC
> is turned on by default in BIND. Incidentally - is it?

   dnssec-enable yes;
and
   dnssec-validation yes;

are the defaults since BIND 9.5

Serving signed zones requires signed zone data to serve.

Validation requires configuration of trust anchors.

AlanC

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 261 bytes
Desc: OpenPGP digital signature
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20100224/3dff6a67/attachment.bin>


More information about the bind-users mailing list