bind autosign - DS distribution

Chris Buxton chris.p.buxton at
Fri Dec 10 05:16:41 UTC 2010

On Dec 9, 2010, at 2:26 PM, Matus UHLAR - fantomas wrote:

> Is it possible(planned) for bind to sign slave zone?
> And, are incremental updates possible with dnssec?
> I'm thinking about hidden master bind loading (un)signed zones and providing
> axfr/ixfr to our public servers

Secure64 makes a product that does this.

- The hidden master creates/updates an unsigned zone.
- Secure64 appliance acts as a slave, transferring the zone in response to notify messages. It then signs the zone, including auto-generating and auto-rotating keys as needed (I believe).
- Secure64 appliance then acts as a second hidden master, replicating the zone out to the regular slaves.

I believe it's implemented using two instances of nsd (from NLnet Labs), one acting as a slave and another acting as a primary master, with some proprietary code in between.

Note: You hinted that the unsigned zone content is generated by some process that would be difficult to modify. Products from my employer and our other competitors would not have as easy a time handling that type of need as this off-the-shelf product from Secure64. If that is not the case, however, I would be happy to talk to you about DNSSEC solutions from BlueCat Networks.

Chris Buxton
BlueCat Networks
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the bind-users mailing list