Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revision Both sides next revision
linux:bind [2015/08/12 14:05]
zagi
linux:bind [2015/08/12 14:06]
zagi
Line 3: Line 3:
 ==== DNSSEC ==== ==== DNSSEC ====
  
-dnssec-keygen -a 7 -b 2048 -n ZONE domena.org +  dnssec-keygen -a 7 -b 2048 -n ZONE domena.org 
-dnssec-keygen -f KSK -a 8 -b 4096 -n ZONE domena.org+  dnssec-keygen -f KSK -a 8 -b 4096 -n ZONE domena.org
  
 copy generated files in /etc/bind/keys. copy generated files in /etc/bind/keys.
Line 13: Line 13:
 put this in zone domena.org put this in zone domena.org
  
-inline-signing yes; +  inline-signing yes; 
-auto-dnssec maintain; +  auto-dnssec maintain; 
-key-directory "/etc/bind/keys/domena.org"; +  key-directory "/etc/bind/keys/domena.org"; 
-sig-validity-interval 3;  // default is 30D+  sig-validity-interval 3;  // default is 30D
  
-use dnssec-dsfromkey to create DS from KSK files.+use dnssec-dsfromkey to create DS DNS records from **KSK files.**
  
  
linux/bind.txt · Last modified: 2015/08/12 14:46 by zagi
CC Attribution-Share Alike 4.0 International
Driven by DokuWiki Recent changes RSS feed Valid CSS Valid XHTML 1.0 ipv6 ready