Closed webvanced closed 6 years ago
This can be done automaticly in powerdns >= 4.1. Setting domain meta data API-RECTIFY=1 after securing a domain and run a rectify domain:
pdnsutil set-meta domain.nl API-RECTIFY 1 pdnsutil rectify-zone domain.nl
I willl close this issue because it can be handled by powerdns itself now.
At this moment i have to manually run pdnsutil rectify-zone to rectify the zone for correct NSEC ordering.
DNSSEC-enabled zones should be rectified after changing the zone data. This can be done by the API automatically after a change when the API-RECTIFY metadata is set. When creating or updating a zone, the “api_rectify” field of the Zone can be set to true to enable this behaviour.
Or the rectifying should be done after updating the zone by PUT /servers/{server_id}/zones/{zone_id}/rectify