Re: [DNSSEC] Validating resolver which is also authoritative: no AD bit set

2009-01-23 Thread Simon Vallet
On Fri, 23 Jan 2009 14:48:23 +0100 Stephane Bortzmeyer wrote: > I configure a BIND 9.5.0 P2 which is both a DNSSEC-validating resolver > and an authoritative server. > > With proper trust anchors, it DNSSEC-validates domains like iis.se or > sources.org and sets the AD bit in the answers to 'di

Re: [DNSSEC] Validating resolver which is also authoritative: no AD bit set

2009-01-23 Thread Alan Clegg
Stephane Bortzmeyer wrote: > I configure a BIND 9.5.0 P2 which is both a DNSSEC-validating resolver > and an authoritative server. > > With proper trust anchors, it DNSSEC-validates domains like iis.se or > sources.org and sets the AD bit in the answers to 'dig +dnssec XXX > iis.se'. > > Except f

[DNSSEC] Validating resolver which is also authoritative: no AD bit set

2009-01-23 Thread Stephane Bortzmeyer
I configure a BIND 9.5.0 P2 which is both a DNSSEC-validating resolver and an authoritative server. With proper trust anchors, it DNSSEC-validates domains like iis.se or sources.org and sets the AD bit in the answers to 'dig +dnssec XXX iis.se'. Except for one domain, generic-nic.net, for which t