How to get AD flag

Stephane Bortzmeyer bortzmeyer at nic.fr
Fri Aug 2 13:58:25 UTC 2013


On Fri, Aug 02, 2013 at 10:49:22AM +0530,
 rams <bramesh80 at gmail.com> wrote 
 a message of 41 lines which said:

> I have 9.7 bind installed and configured recursive.  When i query
> against forwader i am not getting AD flag. Could you please guide me
> how to get AD flag.

Several possible reasons:

1) Unsigned domain. Are you sure you test with a signed domain such as
ietf.org, afnic.fr or nlnetlabs.nl?

2) Broken forwarder (strip the signatures or something like that). Try without it.

3) Wrong anchor (DNS root key). Do you have a trusted-keys or
managed-keys directive and what does it contain?

> remaining answer is correct for signed query

I would prefer that you copy-and-paste this answer. How do you know it
is correct? (See suggestions 1 and 2)


More information about the bind-users mailing list