I've noticed a probable error in dnssec-signzone's man page. Description for option -T says that "the default is the minimum TTL value from the zone's SOA record". But my tests show, that the default is the TTL of the SOA itself. Which by the way makes much more sense, as minimum/negative TTL is usually much lower than SOA's TTL.
Using bind version 9.7.2-P3. Torinthiel
signature.asc
Description: OpenPGP digital signature
_______________________________________________ bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users