Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-12 Thread Stephane Bortzmeyer
On Fri, Jan 07, 2011 at 01:35:59PM +0100, Leen Besselink wrote a message of 58 lines which said: > I would expect it to need authentication tokens too. :-) In almost all registries, this is allowed only to registered registrars. So, even if someone were willing to add an EPP client to PowerDN

Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-07 Thread Leen Besselink
On Fri, Jan 07, 2011 at 11:39:59AM +0100, bert hubert wrote: > On Fri, Jan 07, 2011 at 11:24:12AM +0100, Leen Besselink wrote: > > > But their is one part I'm missing a way to hook up an EPP-client for > > sending the DS-record to the parent-zone. > > This could be added to pdnssec perhaps - is t

Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-07 Thread bert hubert
On Fri, Jan 07, 2011 at 11:24:12AM +0100, Leen Besselink wrote: > A (possibly hidden) supermaster which does all the DNSSEC signing and > the superslaves which only do > zone-trasfers and no online DNSSEC-signing but do understand enough of > the protocol to be able to serve it. This scenario is s

Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-07 Thread Leen Besselink
On 01/06/2011 08:00 PM, bert hubert wrote: > On Thu, Jan 06, 2011 at 11:55:24AM -0500, Mathew Hennessy wrote: >> Excellent! BTW, can PowerDNSSEC operate in the following way as one would >> expect: >> >> PowerDNS supermaster which has DNSSEC RRs but doesn't do DNSSEC (aka >> traditional PowerDNS)

Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-07 Thread Frank Louwers
would be an excellent "way into dnssec". This wouldn't require any change to the existing (non-dnssec) powerdns setups, and would allow us to test with "real" things, easily migrate single domains to a dnssec setup (just change the nameservers), rollback when needed to the old and tested setup

Re: [Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-06 Thread bert hubert
On Thu, Jan 06, 2011 at 11:55:24AM -0500, Mathew Hennessy wrote: > Excellent! BTW, can PowerDNSSEC operate in the following way as one would > expect: > > PowerDNS supermaster which has DNSSEC RRs but doesn't do DNSSEC (aka > traditional PowerDNS) providing data to PowerDNS slaves. If you use t

[Pdns-users] PowerDNSSEC Progress: ready for a first look

2011-01-06 Thread bert hubert
Dear PowerDNS Community, With the help of many of you, we've now brought 'PowerDNSSEC' to the point where it might make sense for you to trial it on test domains. We expect to make move some of our own important domains over to PowerDNSSEC early next week. PowerDNS.COM underlies the commercial DN