Using inline-signing, need to allow dynamic updates.

Thomas Schulz schulz at adi.com
Mon Feb 27 17:07:00 UTC 2017


Right now we have our external view for adi.com set up to use
inline-signing with the following entries in our named.conf file;

 inline-signing yes;
 key-directory "dnssec";
 auto-dnssec maintain;

I now need to allow dynamic updates to support letsencrypt which needs
to add txt records when the certificate is renewed. Can I just add

 allow-update { key keyname-here; };

Or do I need to change the above configuration in some way?

Tom Schulz
Applied Dynamics Intl.
schulz at adi.com


More information about the bind-users mailing list