Crist Clark <cjc+bind-us...@pumpky.net> wrote:
    > Tired of looking at the log messages warning me that inline-signing
    > will be the default in 9.20. I want to convert my 9.18 to using
    > inline-signing.  Right now all of the zones use dnssec-policy and are
    > dynamic.

My experience was that it was best to do bump-in-the-xfer signing.
I created a view "authoritative" loaded all my zones there, then created a
view called "signing", and had the signing view xfer, do-managed-signing, and
serving it.

I have a blog entry somewhere on this, which I can't locate right now.
-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from 
this list

ISC funds the development of this software with paid support subscriptions. 
Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to