Re: private tld

2013-08-21 Thread Maria
On Tue, Aug 20, 2013 at 08:17:03PM -0500, Timothy Morizot wrote: > DNSSEC sign the private TLD and configure its KSK as a trust anchor on the > recursive resolvers. > > Alternatively, you can configure all your recursive resolvers as slaves for > the private zone. Authoritative respons

Re: private tld

2013-08-20 Thread Mark Andrews
In message <20130820221524.ga24...@iano.org>, Maria writes: > My company uses a private tld. We are working on fixing that but the fix is > going to take a while, especially if our sol > ution ends up being trying to register it with icann. > > Our resolvers that all intern

Re: private tld

2013-08-20 Thread Timothy Morizot
DNSSEC sign the private TLD and configure its KSK as a trust anchor on the recursive resolvers. Alternatively, you can configure all your recursive resolvers as slaves for the private zone. Authoritative responses aren't validated on a mixed authoritative/recursive nameserver. Those are the

Re: private tld

2013-08-20 Thread Alan Clegg
On Aug 20, 2013, at 6:15 PM, Maria wrote: > My company uses a private tld. We are working on fixing that but the fix is > going to take a while, especially if our solution ends up being trying to > register it with icann. > > Our resolvers that all internet queries go through

private tld

2013-08-20 Thread Maria
My company uses a private tld. We are working on fixing that but the fix is going to take a while, especially if our solution ends up being trying to register it with icann. Our resolvers that all internet queries go through have a forward zone statement for that tld to some internal name