Hi Matthias, The answer is almost, as long as the zone has a DNSSEC policy configured:
zone "newdomain.de" { type master; file "../master/newdomain.de"; dnssec-policy default; } The only thing not yet fully automated is submitting the DS to the parent. You can do that as soon as named puts the CDS/CDNSKEY records in the zone. Best regards, Matthijs On 4/7/20 10:55 AM, Matthias Fechner wrote: > Dear all, > > is bind (version 9.16.1) able to do all DNSSEC required steps fully by > itself. > > So I only create a new zone for a domain and include it like for > newdomain.de: > zone "newdomain.de" { > type master; > file "../master/newdomain.de"; > ... > } > > After bind was reloaded/restarted, it automatically creates the required > keys and fully maintain the zone, do key rollover, everything required > fully by itself? > > Gruß > Matthias >
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users