9.9.0rc1: example from arm 4.8.3 does not validate

Spain, Dr. Jeffry A. spainj at countryday.net
Wed Jan 18 22:55:21 UTC 2012


> I tried the example from page 23 with a local zone, a trusted key and inline-signing, ...
> But I'm getting no ad-flag

I think that is expected behavior when you query an authoritative server directly. For example, our authoritative server:
dig @ns1.countryday.net countryday.net dnskey +dnssec
also returns no ad flag, but if you run the same query from a DNSSEC-enabled recursive resolver, you will get an ad flag.

Regards, Jeff
 
Jeffry A. Spain
Network Administrator
Cincinnati Country Day School



More information about the bind-users mailing list