Re: Multi Master/Primary Authoritative DNSSEC DNS Nameserver With Synced/Replicated COMMON Dir/Vol For BIND

2024-09-29 Thread Matthijs Mekking
Hi Erik, There is no configuration option for enabling multi-signer in BIND. BIND 9.20 is able to deal with multi-signer setups, but as Mark mentioned earlier, all the coordination needs to be done outside the name server. You may consider MUSIC for this: https://github.com/DNSSEC-Provision

Re: Configuration management of BIND .conf

2024-09-29 Thread Matthew Pounsett
On Tue, Sep 24, 2024 at 7:24 PM John Thurston wrote: > I'm looking for your ideas. What works? What doesn't work? > > Are you leveraging your existing configuration management tools (e.g. > Puppet, Ansible, Chef)? > For OARC's name servers (significantly simpler than yours, but once you're talkin