[Pdns-users] Huge PDNS+DNSSEC setup-Need help

PARTH MONGA kprprl at gmail.com
Fri Apr 13 08:37:51 UTC 2012


Thanks Peter and Jose for a quick reply
Appreciated.

That for sure i will go with NSEC3 but whom to actually  hit
NSEC3-inclusive or NSEC3-narrow

Please advice as not able to figure the difference between both NSEC3 modes.

Thanks & Regards
Parth




On Fri, Apr 13, 2012 at 11:31 AM, Peter van Dijk <
peter.van.dijk at netherlabs.nl> wrote:

> Hi!
>
> On Apr 13, 2012, at 4:51 , José Arthur Benetasso Villanova wrote:
>
> > When you add / remove records, you need to call 'pdnssec rectify-zone
> > example.com' to make sure that the records orders are set properly.
> > This is important to use NSEC, that need the record before and after
> > to give a signed denial of existence. As far I remember, the field
> > content is not use in NSEC, so you can change this at will.
>
> Both NSEC and NSEC3 use the order name field; NSEC3-narrow does not.
>
> Kind regards,
> --
> Peter van Dijk
> Netherlabs Computer Consulting BV - http://www.netherlabs.nl/
>
> _______________________________________________
> Pdns-users mailing list
> Pdns-users at mailman.powerdns.com
> http://mailman.powerdns.com/mailman/listinfo/pdns-users
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.powerdns.com/pipermail/pdns-users/attachments/20120413/3d5a3f82/attachment-0001.html>


More information about the Pdns-users mailing list