project722 <project...@gmail.com> wrote: > > In my named.conf I changed: > > dnssec-validation yes; > > to > > dnssec-validation auto;
Good :-) Next thing to do is delete all trace of managed-keys or mkeys files or trusted-keys configuration, then restart `named`. It will automatically create managed-keys files with the correct contents - it has the current root KSKs built in, so you don't need the bind.keys file. Tony. -- f.anthony.n.finch <d...@dotat.at> http://dotat.at/ South Fitzroy: Northerly or northeasterly 5 or 6. Slight or moderate. Occasional drizzle. Good, occasionally poor at first. _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users