On Mon, Mar 17, 2014 at 11:41:07PM +0200, Mark Elkins wrote:
> I had not thought about that. BIND compiled with pkcs11 and no openssl
> *has* to be used with an HSM (soft and Thales being the two tested
> types) presumably as a Zone signer and can *not* be used as a DNSSEC
> validating resolver.... (IMR)

You *can* use it as a validating resolver, but it probably wouldn't
be very efficient and I don't know why you'd want to. :)

-- 
Evan Hunt -- e...@isc.org
Internet Systems Consortium, Inc.
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to