Files
bind9/lib/dns
Matthijs Mekking c125b721ef Adjust signing code to use kasp
Update the signing code in lib/dns/zone.c and lib/dns/update.c to
use kasp logic if a dnssec-policy is enabled.

This means zones with dnssec-policy should no longer follow
'update-check-ksk' and 'dnssec-dnskey-kskonly' logic, instead the
KASP keys configured dictate which RRset gets signed with what key.

Also use the next rekey event from the key manager rather than
setting it to one hour.

Mark the zone dynamic, as otherwise a zone with dnssec-policy is
not eligble for automatic DNSSEC maintenance.
2019-11-06 22:36:21 +01:00
..
2019-10-02 06:08:59 +00:00
2019-10-01 16:48:55 +02:00
2019-11-06 22:36:21 +01:00
2019-11-06 22:36:21 +01:00
2019-11-06 22:36:21 +01:00
2019-11-06 22:36:21 +01:00
2019-09-12 17:59:28 +10:00
2019-11-06 22:36:21 +01:00
2019-11-06 22:36:21 +01:00