DNSSEC made simple, is this possible?

Mark Elkins mje at posix.co.za
Wed Jan 11 19:02:53 UTC 2012


On Wed, 2012-01-11 at 19:26 +0100, Jan-Piet Mens wrote:
> > Next great thing would be for ISC to support the Soft-HSM that
> > OpenDNSSEC uses. I believe that this would make the step of moving to a
> > real hardware HSM a lot easier (if necessary).
> 
> BIND has supported the PKCS#11 interface (./configure --with-pkcs11)
> since 9.6 IIRC, so it ought to be possible to integrate.

Humm... 
https://lists.isc.org/pipermail/bind-users/2010-October/081508.html
(which was a failed attempt - and cry for help)

Anyone have a successful go at this? (that is replicable)

-- 
  .  .     ___. .__      Posix Systems - (South) Africa
 /| /|       / /__       mje at posix.co.za  -  Mark J Elkins, Cisco CCIE
/ |/ |ARK \_/ /__ LKINS  Tel: +27 12 807 0590  Cell: +27 82 601 0496

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 4007 bytes
Desc: not available
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20120111/40054075/attachment.bin>


More information about the bind-users mailing list