X-Git-Url: http://mj.ucw.cz/gitweb/?a=blobdiff_plain;f=cf.dist%2Fdomains;h=4ec0d214bfc19694a43d8dbd608a7c9a885def92;hb=674bba0d833cd91ca5fa71173b7e2f95c20502fa;hp=e1be8a8d447ff37732e4fabe0c9fe84edf9bf9f5;hpb=0f28cfaa52b633c4a0217345731973565b6ea897;p=nsc-5.git diff --git a/cf.dist/domains b/cf.dist/domains index e1be8a8..4ec0d21 100644 --- a/cf.dist/domains +++ b/cf.dist/domains @@ -1,5 +1,8 @@ ; An example domain table for the NSC +; If you do not want to use DNSSEC, please remove the lines +; commented with "; DNSSEC". + ; Various mandatory things required by RFC 1912, section 4.1 PRIMARY(localhost) REVERSE(127.0.0, localhost) @@ -28,7 +31,10 @@ BLACKHOLE(REV(192.168)) ; A pretty normal example domain (we act as a primary nameserver for it) +DNSSEC(` ; DNSSEC PRIMARY(example.com) +DSFOR(a.example.com) ; DNSSEC +') ; DNSSEC ; It also has a couple of sub-domains and one of them resides on another server @@ -49,8 +55,10 @@ ZONE_OPTIONS() ; Here are reverse delegations for two networks. NSC automatically creates ; the PTR records from A records in all mentioned zones. See cf/{0,1}.0.10. +DNSSEC(` ; DNSSEC REVERSE(10.0.0, example.com, a.example.com) REVERSE(10.1.0, example.com, a.example.com, ip6.example.com) +') ; DNSSEC ; You can even have reverse zones for larger networks