Hi Martijn,
Native zones with replication might be the easiest from a management point of
view (remember to encrypt the replication data so that you don’t expose your
keys), but online signing should work fine with slave zones.
Use "pdnsutil export-zone-key” to export the private key on the mas
Hi Roman ,
Those are Empty Non-Terminals (ENT) - see
https://tools.ietf.org/html/rfc4592#section-2.2.2.
If you’re using the API, then check your default-api-rectify
(https://doc.powerdns.com/authoritative/settings.html#setting-default-api-rectify)
setting. Otherwise, did you run "pdnsutil rect