<div dir="ltr">Hi,<br><br>"You configure parental agents and named will check which DS’s are published. Named won’t complete the<br><div>
roll until it knows the new DS is published."</div><div>=> what is parental agent ? i don't find this term in Bind documentation. From what I understand, you have to specify to Bind that the new DS is published with the command: rndc dnssec -checkds -key <id new ksk> published <my-zone></div><div><br></div><div>"If
it was me, I'd set the KSK to not roll-over automatically, and <br>
instead create a recurring reminder for yourself to initiate the KSK <br>
roll-over manually? That way you'd never get caught out with a KSK <br>
roll-over happening when you weren't prepared for it?
"<br></div><div>=> I don't know if I can get a policy for ZSK and a manual method for KSK. From what I understand if I want to use a policy I have to remove "auto-dnssec maintain;" which is necessary for the manual method right?</div><div><br></div><div>In the meantime, I wonder if I can't stay on the manual method even with a bind 9.18? I read that the auto-dnssec directive might disappear in favor of dnssec-policy. Does that mean that it might not be possible to do it manually anymore? source here => <a href="https://kb.isc.org/v1/docs/dnssec-key-and-signing-policy">https://kb.isc.org/v1/docs/dnssec-key-and-signing-policy</a><br><br></div><div>Regards, <br></div><div>Adrien<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Le jeu. 9 févr. 2023 à 10:35, Mark Andrews <<a href="mailto:marka@isc.org">marka@isc.org</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">You configure parental agents and named will check which DS’s are published. Named won’t complete the<br>
roll until it knows the new DS is published.<br>
<br>
> On 9 Feb 2023, at 19:49, Nick Tait via bind-users <<a href="mailto:bind-users@lists.isc.org" target="_blank">bind-users@lists.isc.org</a>> wrote:<br>
> <br>
> On 9/02/23 05:17, adrien sipasseuth wrote:<br>
>> so it works BUT I need to know more than 48h in advance that the rollover is starting to submit the new KSK to my registar.<br>
>> <br>
>> How can I set this up if it's not with "public-safety"?<br>
> If it was me, I'd set the KSK to not roll-over automatically, and instead create a recurring reminder for yourself to initiate the KSK roll-over manually? That way you'd never get caught out with a KSK roll-over happening when you weren't prepared for it?<br>
> -- <br>
> Visit <a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list<br>
> <br>
> ISC funds the development of this software with paid support subscriptions. Contact us at <a href="https://www.isc.org/contact/" rel="noreferrer" target="_blank">https://www.isc.org/contact/</a> for more information.<br>
> <br>
> <br>
> bind-users mailing list<br>
> <a href="mailto:bind-users@lists.isc.org" target="_blank">bind-users@lists.isc.org</a><br>
> <a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
<br>
-- <br>
Mark Andrews, ISC<br>
1 Seymour St., Dundas Valley, NSW 2117, Australia<br>
PHONE: +61 2 9871 4742 INTERNET: <a href="mailto:marka@isc.org" target="_blank">marka@isc.org</a><br>
<br>
-- <br>
Visit <a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a> to unsubscribe from this list<br>
<br>
ISC funds the development of this software with paid support subscriptions. Contact us at <a href="https://www.isc.org/contact/" rel="noreferrer" target="_blank">https://www.isc.org/contact/</a> for more information.<br>
<br>
<br>
bind-users mailing list<br>
<a href="mailto:bind-users@lists.isc.org" target="_blank">bind-users@lists.isc.org</a><br>
<a href="https://lists.isc.org/mailman/listinfo/bind-users" rel="noreferrer" target="_blank">https://lists.isc.org/mailman/listinfo/bind-users</a><br>
</blockquote></div>