Re: Any chance to do partial sign when RRSIG expires

2018-03-01 Thread Tony Finch
rams wrote: > Currently in bind we are doing auto full sign when RRSIG expires . Is there > any chance to generate only RRSIGS instead of full sign. If you pass the existing signed zone to dnssec-signzone it will incrementally re-sign it as required - see the last example in the man page. Or us

Any chance to do partial sign when RRSIG expires

2018-02-26 Thread rams
Hi, Greetings Currently in bind we are doing auto full sign when RRSIG expires . Is there any chance to generate only RRSIGS instead of full sign. the reason I am asking is when we have large zone and when it happens auto RRSIG expire and full sign, the complete zone is going to full sign and