niclabs / dns-tools

DNS tools for zone signature (file, pkcs11-hsm) and validation, and zone digest (ZONEMD)
MIT License
16 stars 4 forks source link

Sign domain and subdomains together #22

Closed dotsensei closed 3 years ago

dotsensei commented 3 years ago

Hi, Is it possible to sign with your tool both the domain and the subdomains (for which DS and NS records are provided, they use their own DNS servers.)

Thank you.

madestro commented 3 years ago

do you mean 2+ zone files in batch or a huge zone file with all domains and subdomains?

dotsensei commented 3 years ago

Huge zone with all domains and subdomains, or more exactly - a TLD zone.

madestro commented 3 years ago

hmm, if i understand, you have a tld zone with all the hierarchy? e.g: .ple. , .exam.ple. , www.exam.ple. and you want all the hierarchy signed automatically? try it using the TLD as name to sign. We have tested it signing a root zone (using name=.)