This adds a 'dnssec' parameter to the bind::zone define which causes the module to generate keys and sign the zone. Some caveats and breaking changes: 1) Existing non-signed zones will have to be manually moved and signed 2) Signed zones are treated as dynamic |
||
|---|---|---|
| .. | ||
| db.empty | ||
| dnssec-init | ||