Problem with DNSSEC signing zone

2012-07-20 Thread William Thierry SAMEN
Hi all Bind users, i just have a problem with my zone signing output i made all the steps to obtain a good result. 1. Generated KSK and ZSK 2. Add both of keys at the end of my zone file 3. signing my zone with dnssec-signzone command 4. enable dnssec in named options 5. change the

Hi;

2012-05-10 Thread William Thierry SAMEN
Hi, Bind'ers, i'm trying to have a TTL of a zone just by typing a command, but i can't seen which command line i can used to have the solution. Can someone have an idea? is it possible to found that? PS: The zone file is not created by me. For example, i made a dig +dnssec www.google.fr and i wa

generate a set of request DNSsec

2012-04-18 Thread William Thierry SAMEN
Hi, i'm trying to implement DNSsec on my DNS zones and make a test performance to evaluate the charge of DNSsec on my servers. I'm faced with a big problem, *How can i generate a log file for my test?*it's a big problem for me, i'm working on Bind 9.8.1-P1 and i'm using dnsperf to inject requests

Re: How to validate DNSSEC signed record with dig?

2012-02-08 Thread William Thierry SAMEN
Thank you very much for your help i'm going to try it wright now. 2012/2/8 Spain, Dr. Jeffry A. > William: In my tests of DNSSEC, I have used 'auto-dnsssec maintain;' > rather than explicitly signing the zone with dnssec-signzone. I believe I > recall that you are using bind 9.8, so this should

Re: How to validate DNSSEC signed record with dig?

2012-02-08 Thread William Thierry SAMEN
/2/8 Tony Finch > William Thierry SAMEN wrote: > > > > My file zone: > > Er this looks like a key file, not a zone file. The key has been generated > incorrectly: it has a file name where the zone name should be. > > > ; This is a zone-signing key, keyid 12762, for

Re: How to validate DNSSEC signed record with dig?

2012-02-08 Thread William Thierry SAMEN
Hi, thanks for the quick answer, but my problem is still not resolved, i check all your solutions but nothing. I'll show you my file zone which i wanted to sign and the command i used. My file zone: ; This is a zone-signing key, keyid 12762, for *../etc/toto.com.* ; Created: 20120207101131 (Tue

Re: How to validate DNSSEC signed record with dig?

2012-02-07 Thread William Thierry SAMEN
Hi everybody, sorry for my post i'm not read to bring a light to the 1st problem but to find help. I'm triying to sign a zone on Bind 9.8-P1 but i have this message: *dnssec-signzone: fatal: key myKSK.key not at origin* I just want help if someone has been confronted with this kind of message i'