Closed timapril closed 4 years ago
Removing the DS record will allow the NS2 record to e signed in the parent and avoid the DNSSEC parent signing issue.
H/T: Ralf Weber, Sam Weiller, Matt Pounsett
That makes it inconsistent with NS and I think messes up the semantics. NS2 at zone cut should be signed in the child, not the parent.
Removing the DS record will allow the NS2 record to e signed in the parent and avoid the DNSSEC parent signing issue.
H/T: Ralf Weber, Sam Weiller, Matt Pounsett