The Michael W. Lucas DNSSEC book recommends changing NSEC3 salt every time a zone's ZSK changes.
Is this just a matter of a new 'rndc signing' command, or is some action needed to remove the old salt? thanks dn _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users