Re: Can't get Bind to publish CDS/CDNSKEY using dnssec-policy

2021-08-12 Thread Josef Vybíhal
Thank you for pointing me to that issue !2857 , that's exactly what I hit. Now when I see the details, it makes sense. I have cleared the domain from all keys and dnssec-policy settings. Then assigned the dnssec-policy to unsigned domain and

Re: Can't get Bind to publish CDS/CDNSKEY using dnssec-policy

2021-08-12 Thread Matthijs Mekking
Hi, On 12-08-2021 09:02, Josef Vybíhal wrote: Hi, for a second day, I am scratching my head over (automatic) publishing CDS/CDNSKEY records. When I read Matthijs Mekkings KB article at https://kb.isc.org/docs/dnssec-key-and-signing-policy

Can't get Bind to publish CDS/CDNSKEY using dnssec-policy

2021-08-12 Thread Josef Vybíhal
Hi, for a second day, I am scratching my head over (automatic) publishing CDS/CDNSKEY records. When I read Matthijs Mekkings KB article at https://kb.isc.org/docs/dnssec-key-and-signing-policy, I wanted to try dnssec-policy. Up until now, I successfully was using inline-signing with auto-dnssec. I