Hello,

thank you all for the information, and yes, i will need to read the 
documentation again.  I have a clearer idea now of how the dnssec database is 
working.

greetings,

Philip

Op 12/07/19 om 08:25 schreef frank+pdns--- via Pdns-users:


On 11 Jul 2019, at 16:57, Philip Vanmontfort 
<phi...@smartbit.be<mailto:phi...@smartbit.be>> wrote:


goodday,

we change the zone's regularly, but the zone's are generated with puppet.

If we use a predefined key on all servers wouldn't we get into trouble with key 
rollovers? for example rollover differences between name servers that are 
reinstalled?  Or is the only important factor the DS key (wich would be the 
same on all servers)?


Philip,


There’s a difference between key rollovers, which don’t happen automatically 
and you should first figure out why you want to rollover, and signature 
refreshes, which happen automatically in PowerDNS if you use online signing 
(the default mode).

Also note that the DS records don’t contain the key, they contain a hash of the 
key.

Frank
Frank Louwers
PowerDNS Certified Consultant @ Kiwazo.be<http://Kiwazo.be>







_______________________________________________
Pdns-users mailing list
Pdns-users@mailman.powerdns.com<mailto:Pdns-users@mailman.powerdns.com>
https://mailman.powerdns.com/mailman/listinfo/pdns-users

_______________________________________________
Pdns-users mailing list
Pdns-users@mailman.powerdns.com
https://mailman.powerdns.com/mailman/listinfo/pdns-users

Reply via email to