NSEC3/NSEC transition

David Sherman dsherman at bluecatnetworks.com
Thu Feb 14 23:11:30 UTC 2013


Thank you Mark


Regards,
David


-----Original Message-----
From: Mark Andrews [mailto:marka at isc.org] 
Sent: February-14-13 5:39 PM
To: David Sherman
Cc: bind-users at isc.org
Subject: Re: NSEC3/NSEC transition


In message <CB52CF69EC353F4FBC9BA1581123C72E1C73DF62 at TORMBXW01.bluecatnetworks.
corp>, David Sherman writes:
> Thank you,  Mark
> 
> Is it safe to keep -u option for dnssec-signzone in all cases, 
> regardless o= f current actual  NSEC/NSEC3 chains.
> 
> Thanks,
> David

I had forgotten about "-u".  Being a appliance vendor you may want to use it all the time as you have a dashboards etc.

For individuals that are just re-signing a zone, I would say no.

Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org



More information about the bind-users mailing list