mail-in-a-box / mailinabox

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server in a box.
https://mailinabox.email/
Creative Commons Zero v1.0 Universal
13.88k stars 1.43k forks source link

Don't warn about DNSSEC DS record if the domain's DNS is not managed by the box #615

Closed aspdye closed 8 years ago

aspdye commented 8 years ago

Hi there,

Considering the fact that CloudFlare now provides DNSSEC for domains, it is an alternative to the using of the MiaB DNS ;)

Personally - i have created an instance with the hostname (1. Domain) on the MiaB DNS (for TLSA Record, ...). All other secondary domains are at the CloudFlare DNS and use the External DNS Records provided by the MiaB Control Panel. (They dont need an TLSA-Record and the SSHFP-Records [which are not supported by CloudFlare] as i learned by @JoshData here: https://discourse.mailinabox.email/t/dane-tlsa-record-for-secondary-domain/945)

According to https://discourse.mailinabox.email/t/cloudflare-external-dns/928, I think we should change the message that the DS Record is incorrect to: ",this may be ok, if you are using an external DNS with its own DNSSEC Keys".

JoshData commented 8 years ago

If the domain is using external DNS, we should not offer any DNSSEC info for that domain -- it is up to the primary nameserver to do it.

aspdye commented 8 years ago

:+1: we Could make a Checkbox called I am using an External DNS. Then we Would only Check if the Records are correct ;)

JoshData commented 8 years ago

Yep that's #404.