Hello,

I recently rollled out auto-dnssec and inline-signing (v9.9.5), and
today (1-Oct 00:00 UTC) was the first automatic zsk rollover.
According to http://dnsviz.net/d/domainmail.org/dnssec/ it appears
that the SOA is signed by the new zsk, but the rest of the RRs are
still signed by the old.  That concerns me.   Is it as simple as
cached responses?


-Jim P.
_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to