I have local (private) root domain domainX.example and subdomains : 
subdomainY.domainX.example and subdomainZ.domainX.example. I can do chain of 
trust if all zones are In-line signed
zone "domainX.example" {
        type master;
        file "named.domainX.example";
        key-directory "/var/named/keys/zones";
        auto-dnssec maintain;
        inline-signing yes;
    };
zone "subdomainY.domainX.example" {
        type master;
        file "named.subdomainY.domainX.example";
        key-directory "/var/named/keys/zones";
        auto-dnssec maintain;
        inline-signing yes;
    };
zone "subdomainZ.domainX.example" {
        type master;
        file "named.subdomainZ.domainX.example";
        key-directory "/var/named/keys/zones";
        auto-dnssec maintain;
        inline-signing yes;
    };
Or  domainX.example MUST be manually assigned.

Sent from Mail for Windows 10

_______________________________________________
Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe 
from this list

bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to