<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Treehouse Blog &#187; bind</title>
	<atom:link href="http://brady.thtech.net/tag/bind/feed/" rel="self" type="application/rss+xml" />
	<link>http://brady.thtech.net</link>
	<description></description>
	<lastBuildDate>Mon, 09 Jan 2012 04:32:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>DNSSEC at home</title>
		<link>http://brady.thtech.net/2010/07/17/dnssec-at-home/</link>
		<comments>http://brady.thtech.net/2010/07/17/dnssec-at-home/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 02:26:47 +0000</pubDate>
		<dc:creator>balleman</dc:creator>
				<category><![CDATA[Happenings]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[dlv]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dnssec]]></category>
		<category><![CDATA[isc]]></category>

		<guid isPermaLink="false">http://brady.thtech.net/?p=632</guid>
		<description><![CDATA[Since the root zone was signed this week, I spent a bit of time today setting up DNSSEC validation on my home recursive server.  It was relatively painless (so far).  I did opt to not enable DLV though &#8211; not fond of it receiving every host name I resolve. Resources: RHEL RPMs from http://people.redhat.com/atkac/bind/5.6-test/ &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>Since the root zone was signed this week, I spent a bit of time today setting up DNSSEC validation on my home recursive server.  It was relatively painless (so far).  I did opt to not enable DLV though &#8211; not fond of it receiving every host name I resolve.</p>
<p>Resources:</p>
<ul>
<li>RHEL RPMs from <a href="http://people.redhat.com/atkac/bind/5.6-test/">http://people.redhat.com/atkac/bind/5.6-test/</a> &#8211; if someone finds a better source for BIND 9.7+ RHEL RPMs, I&#8217;d like to know.  I had no luck building from the Fedora SRPMs.</li>
<li><a href="http://www.isc.org/community/blog/201007/using-root-dnssec-key-bind-9-resolvers">http://www.isc.org/community/blog/201007/using-root-dnssec-key-bind-9-resolvers</a> &#8211; instructions for setting up BIND to use the root key.</li>
<li><a href="http://fanf.livejournal.com/107310.html">http://fanf.livejournal.com/107310.html</a> &#8211; A more thorough walk-through of setup.</li>
</ul>
<p>One resource I would have liked to find and could not was a deliberately unvalidatable non-root zone/record that could be used to see a validation failure.  If anyone knows of or finds such a thing, please pass it along.  Now we get to wait for .com, .net, etc, to catch up to .bg and .uk in the publishing of DS glue for deeper validation.</p>
<p><strong>UPDATE 7/22/10</strong>:  Just found the following site which makes available bad records for testing purposes: <a href="http://dnssec-tools.org/testzone/index.html">http://dnssec-tools.org/testzone/index.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://brady.thtech.net/2010/07/17/dnssec-at-home/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

