RE: DNSSEC Signing & Key Questions

2011-10-04 Thread Marc Lampo
. Kind regards, Marc Lampo Security Officer EURid From: McConville, Kevin [mailto:kmcconvi...@albany.edu] Sent: 04 October 2011 09:10 PM To: bind-users@lists.isc.org Subject: DNSSEC Signing & Key Questions I’m new to this list, so please bear with me if these are/seem like “newbie” quest

Re: DNSSEC Signing & Key Questions

2011-10-04 Thread Mark Elkins
Played with OpenDNSSEC - and was a bit disappointed. Actually flew to Sweden and attended the course. It works - but acts like a black box - you don't have any finger-poking ability when things go wrong (for fun - we deleted a key out of the HSM - bad idea!) I don't like having to run everything D

Re: DNSSEC Signing & Key Questions

2011-10-04 Thread Tony Finch
McConville, Kevin wrote: > > 1) Is there any way to have the zsk be auto-generated based upon the > inactive date listed in the zsk meta-data? Not yet, though I believe this feature is on the wish list. > 2) With a static zone, are the update-policy local and auto-dnssec > maintain options inv

DNSSEC Signing & Key Questions

2011-10-04 Thread McConville, Kevin
I'm new to this list, so please bear with me if these are/seem like "newbie" questions. We are currently evaluating a DNSSEC implementation. We have several static zones that we would like to implement first. We are currently using ISC Bind 9.7.4 - In the test environment (1) Authoritative dn