Re: nsupdate, dnssec, minimum ttl

2010-06-17 Thread Mark Andrews
In message <4c1a7319.3010...@usc.edu>, Eric Ham writes: > I'm using 9.7.0-P2 to test with dynamic updates via nsupdate along with > setting up dnssec. So far my tests are working well with dynamic updates > and validation of the dnssec records, but I have a question on how the > TTL is set for

Re: nsupdate, dnssec, minimum ttl

2010-06-17 Thread Casey Deccio
On Thu, Jun 17, 2010 at 12:10 PM, Eric Ham wrote: > > It would appear that the NSEC and RRSIG NSEC TTLs are set to my example.com > zone's minimum TTL which is 86400 instead of inheriting the TTL I set of 7200. > >From RFC 4034 (section 4): The NSEC RR SHOULD have the same TTL value as the

nsupdate, dnssec, minimum ttl

2010-06-17 Thread Eric Ham
I'm using 9.7.0-P2 to test with dynamic updates via nsupdate along with setting up dnssec. So far my tests are working well with dynamic updates and validation of the dnssec records, but I have a question on how the TTL is set for the NSEC and RRSIG NSEC records. As a test, when I do the follo