dnssec - DS vs dnssec-signkey

Mark_Andrews at isc.org Mark_Andrews at isc.org
Mon Nov 4 23:26:40 UTC 2002

> bind 9.3 snapshot no longer compiles the dnssec-signkey/makekeyset files.
> I take that this is because we don't need them anymore, due to DS.

	Well keysets still need to be sent to the parent.  Whether we need
	to send self-signed keyset or verify them some other way is up to
	the parent.
> It seems that dnssec-signzone magically finds the right key to reference
> in the DS. I'm guessing that this is due to presence of the keyset- files?

	Yes.  They are used to generate DS records if they are not otherwise
	present in the zone.

