inkblot / puppet-bind

18 stars 81 forks source link

Forward zone for private TLD doesn't work with DNSsec validation #30

Open nprbsg opened 9 years ago

nprbsg commented 9 years ago

The default values for the bind class configure a server with DNSsec enabled and validation enabled. This causes ServFail responses in forward zones for private TLDs due to the lack of proper delegation from the root zone.

beddari commented 9 years ago

Hmm. I think this should be documented, but not sure about changing the defaults. Any suggestions @nprbsg ?

nerdlich commented 8 years ago

Not an issue of this module, imho, rather a limitation of your setup. Ways around this (without deactivating DNSSEC):