Configuring DNSSEC On BIND9 (9.7.3) On Debian Squeeze/Ubuntu 11.10
This guide explains how you can configure DNSSEC on BIND9 (version
9.7.3 that comes with Debian Squeeze/Ubuntu 11.10) on Debian Squeeze and
Ubuntu 11.10. It covers how to enable DNSSEC on authoritative
nameservers (master and slave) and on resolving nameservers, creation of
keys (KSKs and ZSKs), signing of zones, key rolling with rollerd, zone
file checking with donuts, creation of trust anchors, using DLV (DNSSEC
look-aside validation), and getting your DS records into the parent’s
zone.









