Hi Peter
Peter Thomassen via knot-dns-users wrote:
> On 4/13/25 21:59, Michael Grimm via knot-dns-users wrote:
>>> Or RFC 9615:
>>> https://www.knot-dns.cz/docs/3.4/html/modules.html#authsignal-automatic-authenticated-dnssec-bootstrapping-records
>> Interesting, thanks.
>> Now I need to find o
Hi Peter
Peter Thomassen via knot-dns-users wrote:
> On 4/13/25 22:17, Michael Grimm via knot-dns-users wrote:
>> Oh, that list includes RIPE NCC [1]. Does that mean: it is possible to
>> bootstrap DNSSEC for my ip6.arpa zone?
> [...]
>> [1]
>> https://docs.db.ripe.net/Database-Support/Configu
Hi Michael,
On 4/13/25 22:17, Michael Grimm via knot-dns-users wrote:
Oh, that list includes RIPE NCC [1]. Does that mean: it is possible to
bootstrap DNSSEC for my ip6.arpa zone?
[...]
[1]
https://docs.db.ripe.net/Database-Support/Configuring-Reverse-DNS/#automated-update-of-dnssec-delegati
Peter Thomassen via knot-dns-users wrote:
> On 3/31/25 12:30, Libor Peltan via knot-dns-users wrote:
>>> But what about KSK for my reverse zone and DNSKEY "upload to the registrar"?
>>> I do have the feeling I am missing an important part here ;-)
>> Uploading your KSKs to your registrar is out
Hi Michael,
On 4/13/25 21:59, Michael Grimm via knot-dns-users wrote:
Or RFC 9615:
https://www.knot-dns.cz/docs/3.4/html/modules.html#authsignal-automatic-authenticated-dnssec-bootstrapping-records
Interesting, thanks.
Now I need to find out, if that's possible with an ip6.arpa zone …
In g
On 3/31/25 12:30, Libor Peltan via knot-dns-users wrote:
But what about KSK for my reverse zone and DNSKEY "upload to the registrar"?
I do have the feeling I am missing an important part here ;-)
Uploading your KSKs to your registrar is out of scope for us (unless the
registry supports RFC