Inline-signing / dnssec-policy: Signed SOA serial diverges from source serial causing monitoring warnings
Jan-Piet Mens
list at mens.de
Tue Jul 21 16:35:15 UTC 2026
>As a result, they report warnings such as:
those tools are broken.
>Is this independent signed serial expected behavior for BIND 9.18.39 with dnssec-policy and inline-signing?
Yes.
>Is there any supported configuration that preserves the source SOA serial in the served signed zone while still allowing automatic signing and automatic key maintenance?
No, and that is not possible. Consider a zone which is not updates: RRSIGs need to be periodically refreshed which causes the SOA serial to increase so that NOTIFY / XFR to/from secondaries works.
dnssec-policy currently knows: serial-update-method ( date | increment | unixtime ), with "date" creating a YYYYMMDDnn format (with nn between 00 and 99 and more than 100 updates per day rolling over onto "tomorrow".
>If not, would ISC consider adding an optional configuration (for example, a policy or zone option) that allows the served signed zone to retain the source SOA serial where administrators intentionally use YYYYMMDDNN serial numbering?
I am not affiliated with ISC, but I doubt they would, because of the previous answer.
-JP
More information about the bind-users
mailing list