Non-disruptive migration to dnssec-policy possible?

Håkan Lindqvist h+bind at qw.se
Fri Mar 27 11:58:30 UTC 2020


On 2020-03-27 00:34, Shumon Huque wrote:
>
> In fact, "rndc zonestatus" reports the same for a very simple 
> dnssec-policy test on a local zone I did:
>
> $ rndc zonestatus foo.test
> name: foo.test
> type: master
> files: zones/foo.test/zonefile
> serial: 1000000251
> signed serial: 1000000257
> nodes: 5
> last loaded: Wed, 25 Mar 2020 17:52:09 GMT
> secure: yes
> inline signing: yes
> ^^^^^^^^^^^^^^^^^
>

Thank you for pointing this out, I did not think of that rndc zonestatus 
also reflects thisthis.

For reference, I reported this behavior as a bug: 
https://gitlab.isc.org/isc-projects/bind9/-/issues/1709


/Håkan

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20200327/39834dcd/attachment.htm>


More information about the bind-users mailing list