Re: 9.9.0rc1: example from arm 4.8.3 does not validate

2012-01-19 Thread David Forrest
On Thu, 19 Jan 2012, Axel Rau wrote: Am 18.01.2012 um 23:54 schrieb Evan Hunt: I tried the example from page 23 with a local zone, a trusted key and inline-signing, like: [...] But I'm getting no ad-flag: That's normal; authoritative servers don't set the AD bit, validating resolvers do. (

Re: 9.9.0rc1: example from arm 4.8.3 does not validate

2012-01-19 Thread Axel Rau
Am 18.01.2012 um 23:54 schrieb Evan Hunt: >> I tried the example from page 23 with a local zone, a trusted key and >> inline-signing, like: >> [...] >> But I'm getting no ad-flag: > > That's normal; authoritative servers don't set the AD bit, validating > resolvers do. (There's not much point i

RE: 9.9.0rc1: example from arm 4.8.3 does not validate

2012-01-18 Thread Spain, Dr. Jeffry A.
> I tried the example from page 23 with a local zone, a trusted key and > inline-signing, ... > But I'm getting no ad-flag I think that is expected behavior when you query an authoritative server directly. For example, our authoritative server: dig @ns1.countryday.net countryday.net dnskey +dnss

Re: 9.9.0rc1: example from arm 4.8.3 does not validate

2012-01-18 Thread Evan Hunt
> I tried the example from page 23 with a local zone, a trusted key and > inline-signing, like: > [...] > But I'm getting no ad-flag: That's normal; authoritative servers don't set the AD bit, validating resolvers do. (There's not much point in having an authoritative server validate its own ans

9.9.0rc1: example from arm 4.8.3 does not validate

2012-01-18 Thread Axel Rau
Hi all, I tried the example from page 23 with a local zone, a trusted key and inline-signing, like: --- trusted-keys { "example.com." 257 3 5 "AwEAAd5l859ggW8ZpVAQxEmugl+N/klWH+kFpcoQYGd3ngB6381lva2E IUXa2iOxJPmvYut96zUqhprlUfuEBvhU21Dd8dv7rr3Q5a+UT5XA9fUe 8ebpRn+R2YT/WPJPnwww1pEaA0DIU