From 982e54af4a2decd6f1606ce4e0f3aa783cccbf3f Mon Sep 17 00:00:00 2001 From: Gert van Dijk Date: Sun, 31 Mar 2019 19:25:21 +0200 Subject: [PATCH] docs: Improve "BIND-mode operation" for DNSSEC Also: * Mention that not just keys are part of this database, but also DNSSEC domain metadata. * Link to the pdns.conf setting. --- docs/dnssec/modes-of-operation.rst | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/docs/dnssec/modes-of-operation.rst b/docs/dnssec/modes-of-operation.rst index f6679dafbd..25525eb054 100644 --- a/docs/dnssec/modes-of-operation.rst +++ b/docs/dnssec/modes-of-operation.rst @@ -162,13 +162,14 @@ The signing and hashing algorithms are described in :ref:`dnssec-online-signing` BIND-mode operation ------------------- -The :doc:`bindbackend <../backends/bind>` can manage keys in an -SQLite3 database without launching a separate gsqlite3 backend. - -To use this mode, add -``bind-dnssec-db=/var/db/bind-dnssec-db.sqlite3`` to pdns.conf, and run -``pdnsutil create-bind-db /var/db/bind-dnssec-db.sqlite3``. Then, -restart PowerDNS. +The :doc:`bindbackend <../backends/bind>` can manage keys and other +DNSSEC-related :doc:`domain metadata <../domainmetadata>` in an SQLite3 +database without launching a separate gsqlite3 backend. + +To use this mode, run +``pdnsutil create-bind-db /var/db/bind-dnssec-db.sqlite3`` and set +:ref:`setting-bind-dnssec-db` in pdns.conf to the path of the created +database. Then, restart PowerDNS. .. note:: This SQLite database is different from the database used for the regular :doc:`SQLite 3 backend <../backends/generic-sqlite3>`. -- 2.47.2