Requesting tips on setting TTLs so that expired RRSIG data doesn't stay in the zone

GS Bryan chifuyu at anime.my
Fri Dec 14 10:48:47 UTC 2012


Reference: http://dnssec-debugger.verisignlabs.com/imouto.my

How to configure named (version BIND 9.9.2-P1-RedHat-9.9.2-2.P1.el5)
so that expired RRSIG data doesn't stay in the zone? I heard it has
omething to do with the TTL of the zone (the expiry timer in that
zone's SOA). The named.conf has the 'sig-validity-interval 21 8;' line
it in, so how then I can change the expire timer so that stale RRSIG
data doesn't stay in the zone?


Thanks.



More information about the bind-users mailing list