dnssec-validation auto vs yes

Shawn Zhou shawnzhou00 at yahoo.com
Wed Jun 12 23:40:27 UTC 2019


Hi,
The default BIND9 installation for CentOS7 has dnssec-validation set to "yes" and it also includes managed-keys as well. Do those managed-keys get updated automatically? It is not clear from reading https://ftp.isc.org/isc/dnssec-guide/html/dnssec-guide.html#dnssec-validation-explained that these managed-keys will get updated automatically if dnssec-validation is not set to "auto".
[root at centos-linux ~]# named -vBIND 9.9.4-RedHat-9.9.4-73.el7_6 (Extended Support Version)[root at centos-linux ~]# grep named.root.key /etc/named.confinclude "/etc/named.root.key";[root at centos-linux ~]# cat /etc/named.root.keymanaged-keys {        # ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml        # for current trust anchor information.        #        # This key (19036) is to be phased out starting in 2017. It will        # remain in the root zone for some time after its successor key        # has been added. It will remain this file until it is removed from        # the root zone.        . initial-key 257 3 8 "AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=";
        # This key (20326) is to be published in the root zone in 2017.        # Servers which were already using the old key should roll to the        # new # one seamlessly.  Servers being set up for the first time        # can use either of the keys in this file to verify the root keys        # for the first time; thereafter the keys in the zone will be        # trusted and maintained automatically.        . initial-key 257 3 8 "AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3 +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF 0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN R1AkUTV74bU=";};

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20190612/af77aad0/attachment.html>


More information about the bind-users mailing list