Re: Problem with an unsigned private subzone of a signed public zone

2010-04-19 Thread Tony Finch
On 19 Apr 2010, at 20:40, Chris Thompson wrote: On Apr 19 2010, I wrote: [...] Of course, it could also prove there is no DS record for private.cam.ac.uk, but the absence of NS records as well apparently makes it think that private.cam.ac.uk is bogus. More experiments indicate that somethi

Re: Problem with an unsigned private subzone of a signed public zone

2010-04-19 Thread Chris Thompson
On Apr 19 2010, I wrote: [...] Of course, it could also prove there is no DS record for private.cam.ac.uk, but the absence of NS records as well apparently makes it think that private.cam.ac.uk is bogus. More experiments indicate that something changed between 9.6.1-P3 and 9.6.2rc1 - previousl

Re: Problem with an unsigned private subzone of a signed public zone

2010-04-19 Thread Mark Andrews
In message , Chris Thompson writes: > We have a forward zone (private.cam.ac.uk) and reverse zones (e.g. > 16.172.in-addr.arpa) for a subset of RFC1918 addresses that are > routed throughout, but not outside, the university network. Access > to these zones is restricted to that network, as the re

Problem with an unsigned private subzone of a signed public zone

2010-04-19 Thread Chris Thompson
We have a forward zone (private.cam.ac.uk) and reverse zones (e.g. 16.172.in-addr.arpa) for a subset of RFC1918 addresses that are routed throughout, but not outside, the university network. Access to these zones is restricted to that network, as the results would not be meaningful elsewhere. The