Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.protocols.dns.bind > #15937

AW: How to prepublish additional DNSKEY

From Klaus Darilion <klaus.darilion@nic.at>
Newsgroups comp.protocols.dns.bind
Subject AW: How to prepublish additional DNSKEY
Date 2020-07-09 11:51 +0200
Message-ID <mailman.657.1594288242.942.bind-users@lists.isc.org> (permalink)
References <3E18C1A0C550C44DA156DA5DA8ECCC6AB622808F@NICS-EXCH2.sbg.nic.at> <alpine.DEB.2.20.2007081628490.9145@grey.csi.cam.ac.uk> <3E18C1A0C550C44DA156DA5DA8ECCC6AB622A510@NICS-EXCH2.sbg.nic.at>

Show all headers | View raw


> > So, how is the correct process to add an additional DNSKEY (only the public
> key is known).
> 
> I think you are looking for `dnssec-importkey`.

Indeed. I imported the key and got a .key and .private file. I put those files in the same directory as the other keys, gave read permissions to bind and executed:
rndc loadkeys myzone
rndc sign myzone

But the additional key is not added to the reponse of DNSKEY queries.

I am using Bind - 9.12.2-P2. Is this supported by Bind 9.12? (upgrade/downgrade is currently not possible)

Thanks
Klaus

Back to comp.protocols.dns.bind | Previous | Next | Find similar


Thread

AW: How to prepublish additional DNSKEY Klaus Darilion <klaus.darilion@nic.at> - 2020-07-09 11:51 +0200

csiph-web