inkblot / puppet-bind

18 stars 82 forks source link

Support DNSSEC single type signing scheme without ZSK #157

Open pecharmin opened 4 years ago

pecharmin commented 4 years ago

Add option to sign DNSSEC zones initially without a zone signing key as a single type signing scheme. The DNSSEC RFC allows to sign all records of a zone only with a single key signing key.

References: