Tony Finch dot at
Mon Apr 16 08:42:57 UTC 2018

Philip Prindeville <philipp_subx at> wrote:
> It mostly works but doesn’t entirely support partial zone
> delegation via RFC-2317.

You should find some useful guidance in section 9 of

At the moment you'll have to implement the CNAME chasing yourself; I
really ought to find the time to revive that draft and add built-in
support to `nsupdate`.

> Since it’s local, I could do it on localhost:53 trusted without having
> to mess with key management, etc.

`update-policy local` and `nsupdate -l` are your friends.

