On Mon, Mar 17, 2014 at 11:41:07PM +0200, Mark Elkins wrote: > I had not thought about that. BIND compiled with pkcs11 and no openssl > *has* to be used with an HSM (soft and Thales being the two tested > types) presumably as a Zone signer and can *not* be used as a DNSSEC > validating resolver.... (IMR)
You *can* use it as a validating resolver, but it probably wouldn't be very efficient and I don't know why you'd want to. :) -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users