Re: private trust anchor

2013-02-11 Thread Evan Hunt
> Type forward? Really? I didn't expect that to come from someone at ISC. D'oh, embarrassed now. > Use 'type stub' instead, with a masters statement rather than a > forwarders statement. Chris is correct, both options work, stub is better. -- Evan Hunt -- e...@isc.org Internet Systems Consorti

Re: private trust anchor

2013-02-11 Thread Chris Buxton
On Feb 10, 2013, at 3:26 PM, Evan Hunt wrote: > Then configure the > zones as "type forward", with "forwarders" pointing to the authoritative > server(s) for your zones. The resolver will then forward queries for those > names to the authoritative servers, and validate the responses. Type forwar

Re: private trust anchor

2013-02-10 Thread Mark Andrews
In message <20130210225742.ga9...@bewilderbeast.blackhelicopters.org>, "Michael W. Lucas" writes: > Hi, > > Is there a way to set up a private trust anchor for internal-only > zones with BIND 9.9? > > I have some local and RFC1918 zones that I'd like to

Re: private trust anchor

2013-02-10 Thread Michael W. Lucas
On Sun, Feb 10, 2013 at 11:26:27PM +, Evan Hunt wrote: > On Sun, Feb 10, 2013 at 05:57:42PM -0500, Michael W. Lucas wrote: > > Is there a way to set up a private trust anchor for internal-only > > zones with BIND 9.9? > > > > I have some local and RFC1918 zones

Re: private trust anchor

2013-02-10 Thread Evan Hunt
On Sun, Feb 10, 2013 at 05:57:42PM -0500, Michael W. Lucas wrote: > Is there a way to set up a private trust anchor for internal-only > zones with BIND 9.9? > > I have some local and RFC1918 zones that I'd like to secure. It seems > I should be able to configure a private

private trust anchor

2013-02-10 Thread Michael W. Lucas
Hi, Is there a way to set up a private trust anchor for internal-only zones with BIND 9.9? I have some local and RFC1918 zones that I'd like to secure. It seems I should be able to configure a private trust anchor and use that key to sign these zones. I've found, related docs, like dr