NSEC3/NSEC transition

David Sherman dsherman at bluecatnetworks.com
Thu Feb 14 16:41:15 UTC 2013


Hi,

If dynamic signing is used with BIND 9.8, what is the recommended procedure to switch from NSEC3-signed zone to NSEC-signed without changing existing DNSKEYs (currently RSA/SHA-512 algorithms are used for both ZSK and KSK)?
Any specific options for dnssec-signzone?

Thanks,
David



More information about the bind-users mailing list