Testing KASP, CDS, and .ch

Jim Popovitch jimpop at domainmail.org
Fri Apr 9 21:49:10 UTC 2021


On April 9, 2021 8:21:33 PM UTC, "John W. Blue via bind-users" <bind-users at lists.isc.org> wrote:
>Sorry .. clicked send too soon.
>
>Found this via google:
>
>https://docs.gandi.net/en/domain_names/advanced_users/dnssec.html
>
>"You can not add DS keys as we compute it for you with the KSK or ZSK, then we send it to the registry."
>
>So it looks like the owner of domainmail.ch must get the DS from Gandi???  I wouldn't know how that would work exactly but clearly a conversation is needed with Gandi.
>
>Good hunting.

Thanks for trying but i think you're missing the point of this thread.  I'm not asking about how to configure DNSSEC the traditional way.   

Btw, one *can* manually setup a DS RR at Gandi, but they take and decode the actual key data not the DS.


-Jim P 


More information about the bind-users mailing list