Validating zones as a slave? (Fw: [DNSOP] I-D Action: draft-ietf-dnsop-root-loopback-04.txt)

Paul Vixie paul at redbarn.org
Wed Sep 16 10:56:51 UTC 2015



Tony Finch wrote:
> Paul Vixie <paul at redbarn.org> wrote:
>> what behaviour would you have instead?
>
> Continue to use the old zone until a valid version can be transferred.

in defiance of the SOA timing parameters (zone expiry)?

in defiance of the DNSSEC timing parameters (signature validity period)?

my view is, ignoring bad zones is fine, but will not prevent zone or
signature expiration.

-- 
Paul Vixie


More information about the bind-workers mailing list