Validating a DNSSEC installation
Mark Andrews
marka at isc.org
Tue Jun 16 02:33:42 UTC 2009
In message <69BEB178-F30D-4AC2-8E7A-B13C1F5F85CF at menandmice.com>, Chris Buxton
writes:
> On Jun 13, 2009, at 4:59 AM, Erik Lotspeich wrote:
> > Is it normal that a validating resolver can't validate a domain it is
> > authoritative for?
>
> Absolutely. As Alan Clegg wrote not long ago on this list, this is why
> a DNSSEC validating resolver should not be authoritative for any
> signed zones.
>
> Chris Buxton
> Professional Services
> Men & Mice
That's also why there is the "recursion-only" option with
view selection.
> _______________________________________________
> bind-users mailing list
> bind-users at lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: marka at isc.org
More information about the bind-users
mailing list