[Pdns-users] bind backend and dnssec database

Philip Vanmontfort philip at smartbit.be
Fri Jul 12 14:07:49 UTC 2019


thank you all for the information, and yes, i will need to read the documentation again.  I have a clearer idea now of how the dnssec database is working.



Op 12/07/19 om 08:25 schreef frank+pdns--- via Pdns-users:

On 11 Jul 2019, at 16:57, Philip Vanmontfort <philip at smartbit.be<mailto:philip at smartbit.be>> wrote:


we change the zone's regularly, but the zone's are generated with puppet.

If we use a predefined key on all servers wouldn't we get into trouble with key rollovers? for example rollover differences between name servers that are reinstalled?  Or is the only important factor the DS key (wich would be the same on all servers)?


There’s a difference between key rollovers, which don’t happen automatically and you should first figure out why you want to rollover, and signature refreshes, which happen automatically in PowerDNS if you use online signing (the default mode).

Also note that the DS records don’t contain the key, they contain a hash of the key.

Frank Louwers
PowerDNS Certified Consultant @ Kiwazo.be<http://Kiwazo.be>

Pdns-users mailing list
Pdns-users at mailman.powerdns.com<mailto:Pdns-users at mailman.powerdns.com>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.powerdns.com/pipermail/pdns-users/attachments/20190712/67655aca/attachment.html>

More information about the Pdns-users mailing list