Re: BIND and DNSSEC

2012-11-01 Thread Sten Carlsen
On 02/11/12 2:08, Barry S. Finkel wrote: > On 11/1/2012 3:31 PM, Sten Carlsen wrote: >> The typical server setup (for own servers) is that one name is used for >> setting up e.g. the mail server, the ideal situation for everybody is >> that whether I am in house or visiting you, if I have any int

Re: BIND and DNSSEC

2012-11-01 Thread Barry S. Finkel
On 11/1/2012 3:31 PM, Sten Carlsen wrote: The typical server setup (for own servers) is that one name is used for setting up e.g. the mail server, the ideal situation for everybody is that whether I am in house or visiting you, if I have any internet access, I can read and send mail. Now if the

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:45 AM, Alan Clegg wrote: > > On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > >> I recommend using "auto-dnssec maintain" so named keeps the zone signed, >> instead of dnssec-signzone. > > I do as well, and this will be documented in the next version of this > document.

Re: BIND and DNSSEC

2012-11-01 Thread Sten Carlsen
On 01/11/12 12:26, Alan Clegg wrote: On Nov 1, 2012, at 7:14 AM, Kobus Bensch wrote: Is that because split horizon doubles admin or because its bad all together? I have been using split horizon for many years now and found it very useful. Any thoughts from any on the list would be most welc

Re: BIND and DNSSEC

2012-11-01 Thread Chris Thompson
On Nov 1 2012, Jan-Piet Mens wrote: I do as well, and this will be documented in the next version of this document. I believe you've mentioned that here before. Several times. Today. ;-)  "What I tell you three times is true.” The Bellman, pp Lewis Carroll -- Chris Thompson Email: c...@ca

Re: BIND and DNSSEC

2012-11-01 Thread Jan-Piet Mens
> I do as well, and this will be documented in the next version of this > document. I believe you've mentioned that here before. Several times. Today. ;-) -JP ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe fr

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > I recommend using "auto-dnssec maintain" so named keeps the zone signed, > instead of dnssec-signzone. I do as well, and this will be documented in the next version of this document. AlanC -- Alan Clegg | +1-919-355-8851 | a...@clegg.com

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > I recommend using "auto-dnssec maintain" so named keeps the zone signed, > instead of dnssec-signzone. I do as well, and this will be documented in the next version of this document. AlanC -- Alan Clegg | +1-919-355-8851 | a...@clegg.com

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > I recommend using "auto-dnssec maintain" so named keeps the zone signed, > instead of dnssec-signzone. I do as well, and this will be documented in the next version of this document. AlanC -- Alan Clegg | +1-919-355-8851 | a...@clegg.com

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > I recommend using "auto-dnssec maintain" so named keeps the zone signed, > instead of dnssec-signzone. I do as well, and this will be documented in the next version of this document. AlanC -- Alan Clegg | +1-919-355-8851 | a...@clegg.com __

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:34 AM, Tony Finch wrote: > I recommend using "auto-dnssec maintain" so named keeps the zone signed, > instead of dnssec-signzone. I do as well, and this will be documented in the next version of this document. AlanC -- Alan Clegg | +1-919-355-8851 | a...@clegg.com __

Re: BIND and DNSSEC

2012-11-01 Thread Kobus Bensch
;Alan Clegg" To: "Kobus Bensch" Cc: bind-users@lists.isc.org Sent: Thursday, 1 November, 2012 11:26:31 AM Subject: Re: BIND and DNSSEC On Nov 1, 2012, at 7:14 AM, Kobus Bensch wrote: > Is that because split horizon doubles admin or because its bad all together? > > I have

Re: BIND and DNSSEC

2012-11-01 Thread Tony Finch
Feng He wrote: > > Take a look at: > http://www.dnssec.lk/docs/DNSSEC_in_6_minutes.pdf I recommend using "auto-dnssec maintain" so named keeps the zone signed, instead of dnssec-signzone. Tony. -- f.anthony.n.finchhttp://dotat.at/ Forties, Cromarty: East, veering southeast, 4 or 5, occasion

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 7:14 AM, Kobus Bensch wrote: > Is that because split horizon doubles admin or because its bad all together? > > I have been using split horizon for many years now and found it very useful. > Any thoughts from any on the list would be most welcomed. Crafted for a private rep

Re: BIND and DNSSEC

2012-11-01 Thread Kobus Bensch
bus Bensch" Cc: "Feng He" , bind-users@lists.isc.org Sent: Thursday, 1 November, 2012 11:08:10 AM Subject: Re: BIND and DNSSEC On Nov 1, 2012, at 3:02 AM, Kobus Bensch wrote: > Thank you for this. Had a look and it seems fairly easy. Not sure if that is > a flippant remark.

Re: BIND and DNSSEC

2012-11-01 Thread Alan Clegg
On Nov 1, 2012, at 3:02 AM, Kobus Bensch wrote: > Thank you for this. Had a look and it seems fairly easy. Not sure if that is > a flippant remark. As the author of this document, I must say thanks. Deploying DNSSEC is not hard. It's the care and feeding after-the-fact (key rollover) that y

Re: BIND and DNSSEC

2012-11-01 Thread Kobus Bensch
Thank you for this. Had a look and it seems fairly easy. Not sure if that is a flippant remark. A question: is implementing dnssec a good enough reason to abandon split horizon DNS? Kobus Sent from my iPhone On 1 Nov 2012, at 02:01, Feng He wrote: > 于 2012-10-31 23:05, Kobus Bensch 写道: >

Re: BIND and DNSSEC

2012-10-31 Thread Feng He
? 2012-10-31 23:05, Kobus Bensch ??: Can anybody point me in the direction of a good guide on setting up BIND split horizon DNS and DNSSEC? Take a look at: http://www.dnssec.lk/docs/DNSSEC_in_6_minutes.pdf ___ Please visit https://lists.isc.org/mailma

BIND and DNSSEC

2012-10-31 Thread Kobus Bensch
Hi Can anybody point me in the direction of a good guide on setting up BIND split horizon DNS and DNSSEC? Thanks in advance Kobus -- ___ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users