> I tried the example from page 23 with a local zone, a trusted key and > inline-signing, ... > But I'm getting no ad-flag
I think that is expected behavior when you query an authoritative server directly. For example, our authoritative server: dig @ns1.countryday.net countryday.net dnskey +dnssec also returns no ad flag, but if you run the same query from a DNSSEC-enabled recursive resolver, you will get an ad flag. Regards, Jeff Jeffry A. Spain Network Administrator Cincinnati Country Day School _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list [email protected] https://lists.isc.org/mailman/listinfo/bind-users

