NSEC3/NSEC transition
    David Sherman 
    dsherman at bluecatnetworks.com
       
    Thu Feb 14 23:11:30 UTC 2013
    
    
  
Thank you Mark
Regards,
David
-----Original Message-----
From: Mark Andrews [mailto:marka at isc.org] 
Sent: February-14-13 5:39 PM
To: David Sherman
Cc: bind-users at isc.org
Subject: Re: NSEC3/NSEC transition
In message <CB52CF69EC353F4FBC9BA1581123C72E1C73DF62 at TORMBXW01.bluecatnetworks.
corp>, David Sherman writes:
> Thank you,  Mark
> 
> Is it safe to keep -u option for dnssec-signzone in all cases, 
> regardless o= f current actual  NSEC/NSEC3 chains.
> 
> Thanks,
> David
I had forgotten about "-u".  Being a appliance vendor you may want to use it all the time as you have a dashboards etc.
For individuals that are just re-signing a zone, I would say no.
Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org
    
    
More information about the bind-users
mailing list