Re: BIND, DNSSEC & AD

2012-06-30 Thread Mark Andrews
If you don't want to run named on Windows, it supports dynamic updates with GSS-TSIG + DNSSEC. In message <4feed285.7060...@strotmann.de>, "Carsten Strotmann (private)" writes: > Hello John, > > On 6/29/12 4:52 PM, John Williams wrote: > > The purpose behind this is not to protect the internal

Re: BIND, DNSSEC & AD

2012-06-30 Thread Carsten Strotmann (private)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello John, On 6/29/12 4:52 PM, John Williams wrote: > The purpose behind this is not to protect the internal AD DNS from > hijacking. But rather to allow internal clients to run DNSSEC > related queries without having to reference external resolver