> How would BIND sign a zone that is in a Database? Can BIND do this? > ALL examples of using DNSSEC have been with flat files.
DNSSEC with SQL isn't supported in BIND 9 (yet?). IIRC, it can return signed responses for records that do exist, but it can't return proper signed negative responses for records that don't. BIND 10 does have a SQL data source that's fully DNSSEC compliant. It's not really production-ready yet, but you can check out the work in progress if you like: https://bind10.isc.org. -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. _______________________________________________ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users