Re: DNSSEC validation via DLV

2019-07-18 Thread Mark Elkins
That I understand. Use me (Posix) then, full DNSSEC support. https://vweb.co.za. If you like, run your DNS wherever you want, just use me at the Registrar. Unfortunately, very few Registrars in ZA-Land have implemented DNSSEC support - despite ZA having a very high percentage of DNSSEC resolver

Re: DNSSEC validation via DLV

2019-07-18 Thread Mal via bind-users
On 19/07/2019 9:27 am, p...@vspace.co.za wrote: > > Problem being, no options exist as to export the DS record of co.za, com.au > or net.au domains to the respective registrars, being namecheap.com and > axxess.co.za. > Change registry right ? Crazy domains supports them for the ".com.au"

RE: DNSSEC validation via DLV

2019-07-18 Thread peek
By all means, not a difficult process at all. I have DNSSEC enabled and fully operational on .com domains. Problem being, no options exist as to export the DS record of co.za, com.au or net.au domains to the respective registrars, being namecheap.com and axxess.co.za. Noted that namecheap.com

Re: factor addresses out of 'forwarders' statement

2019-07-18 Thread Grant Taylor via bind-users
On 7/18/19 3:24 PM, John Thurston wrote: I have a number of 'forward' zones defined. Many of them look exactly the same except for their name. It would be helpful to abstract the addresses of my forwarders out and name them only once. But I can't find any way to do this. An ACL doesn't make s

factor addresses out of 'forwarders' statement

2019-07-18 Thread John Thurston
I have a number of 'forward' zones defined. Many of them look exactly the same except for their name. It would be helpful to abstract the addresses of my forwarders out and name them only once. But I can't find any way to do this. An ACL doesn't make sense. A 'masters' list doesn't work. Is t

Re: DNSSEC validation via DLV

2019-07-18 Thread Mal via bind-users
Not a difficult process really.. -Configure a DNSSEC enabled name server -Create a some zone keys (dnssec-keygen) -Sign your zone (dnssec-signzone) -Update your nameserver configuration to point to the signed zone file -Export your DS records (dsset) to the domain registration company (EPP). Con

Re: DNSSEC validation via DLV

2019-07-18 Thread Mark Elkins
I  can't comment on com.au (but looking up the Nameservers, I see the AD bit set - so DNSSEC appears to be in use.. However, co.za (and net.oza, org.za & web.za) which are managed by the ZACR (and DNS) - they are all signed and I personally have domains under these second levels - all running