DNAME will not work with DNSSEC.
DNAME only work with the sub-tree, while DNSSEC is at the domain level.

taking the example:
klam.biz   IN DNAME klam.com

DNSSEC will try to find keys for klam.biz NOT klam.com, which results in DNSSEC failure.

It looks like the only way to do this is to point the zones at a single zone file. however I am not sure that that will work as smoothly as I would like.

--
John Allen
KLaM
------------------------------------------
Why do psychics have to ask your name?!

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to