proper setup of dnssec-validation to _always_ resolve, and retrieve DATA and status flags ?

dchilton+bind at dchilton+bind at
Tue May 10 06:19:09 UTC 2011

On Tue, 10 May 2011 16:15 +1000, "Mark Andrews" <marka at> wrote:
> > looks good, right?
> yes.

MANY thanks!  i wouldn't have easily found this ...

> DNSSEC only needs wristwatch time accuracy however it is easy to
> get the time wrong if the server is configured in the wrong timezone.
> The error was equal to the local time offset from UTC which indicates
> it was running in UTC but set with the local time.

not sure how to read that.  now that my time's correct again, can/should
I leave the server as is?  or is there a specific recommendation for
time setup on a DNS server?

Thanks again,


