Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision | Next revision Both sides next revision | ||
linux:bind [2015/08/12 14:05] zagi |
linux:bind [2015/08/12 14:06] zagi |
||
---|---|---|---|
Line 3: | Line 3: | ||
==== DNSSEC ==== | ==== DNSSEC ==== | ||
- | dnssec-keygen -a 7 -b 2048 -n ZONE domena.org | + | |
- | dnssec-keygen -f KSK -a 8 -b 4096 -n ZONE domena.org | + | dnssec-keygen -f KSK -a 8 -b 4096 -n ZONE domena.org |
copy generated files in / | copy generated files in / | ||
Line 13: | Line 13: | ||
put this in zone domena.org | put this in zone domena.org | ||
- | inline-signing yes; | + | |
- | auto-dnssec maintain; | + | auto-dnssec maintain; |
- | key-directory "/ | + | key-directory "/ |
- | sig-validity-interval 3; // default is 30D | + | sig-validity-interval 3; // default is 30D |
- | use dnssec-dsfromkey to create DS from KSK files. | + | use dnssec-dsfromkey to create DS from **KSK files.** |