Re: Almost Ready for DNS-SEC but Slightly Confused in Home Stretch

2010-12-11 Thread Michael Sinatra
On 12/10/10 08:17, Martin McCormick wrote: As a reminder, none of this is on our master DNS yet so we are still doing the normal activities. Our firewalls are supposed to be adjusted to allow the 4096-byte DNS packets in the next day or so so all the testing is being done on another box

Re: Almost Ready for DNS-SEC but Slightly Confused in Home Stretch

2010-12-10 Thread Kevin Oberman
> Date: Fri, 10 Dec 2010 10:17:57 -0600 > From: Martin McCormick > Sender: bind-users-bounces+oberman=es@lists.isc.org > > On my test box, I am not seeing any errors so I think we are > signing the test zone. The dnssec part of named.conf options > looks like: > > dnssec-enable yes; > dnssec

Re: Almost Ready for DNS-SEC but Slightly Confused in Home Stretch

2010-12-10 Thread Alan Clegg
On 12/10/2010 11:17 AM, Martin McCormick wrote: > Is there, somewhere, a linear description of this > process that starts out like: > > 1. Do this. > > and leading up to > > x. Congratulations! you have dnssec working. > > None of these steps in the puzzle have been hard, so far, but >

Almost Ready for DNS-SEC but Slightly Confused in Home Stretch

2010-12-10 Thread Martin McCormick
On my test box, I am not seeing any errors so I think we are signing the test zone. The dnssec part of named.conf options looks like: dnssec-enable yes; dnssec-validation yes; dnssec-lookaside auto; managed-keys-directory "/etc/namedb/working"; In the actual zone, I have: zone