.PP
\-x
.RS 4
-Only sign the DNSKEY RRset with key\-signing keys, and omit signatures from zone\-signing keys\&. (This is similar to the
+Only sign the DNSKEY, CDNSKEY, and CDS RRsets with key\-signing keys, and omit signatures from zone\-signing keys\&. (This is similar to the
\fBdnssec\-dnskey\-kskonly yes;\fR
zone option in
\fBnamed\fR\&.)
<dt><span class="term">-x</span></dt>
<dd>
<p>
- Only sign the DNSKEY RRset with key-signing keys, and omit
- signatures from zone-signing keys. (This is similar to the
+ Only sign the DNSKEY, CDNSKEY, and CDS RRsets with
+ key-signing keys, and omit signatures from zone-signing
+ keys. (This is similar to the
<span class="command"><strong>dnssec-dnskey-kskonly yes;</strong></span> zone option in
<span class="command"><strong>named</strong></span>.)
</p>
When this option and <span class="command"><strong>update-check-ksk</strong></span>
are both set to <code class="literal">yes</code>, only key-signing
keys (that is, keys with the KSK bit set) will be used
- to sign the DNSKEY RRset at the zone apex. Zone-signing
- keys (keys without the KSK bit set) will be used to sign
- the remainder of the zone, but not the DNSKEY RRset.
+ to sign the DNSKEY, CDNSKEY, and CDS RRsets at the zone apex.
+ Zone-signing keys (keys without the KSK bit set) will be used
+ to sign the remainder of the zone, but not the DNSKEY RRset.
This is similar to the
<span class="command"><strong>dnssec-signzone -x</strong></span> command line option.
</p>
matching <span class="command"><strong>cookie-secret</strong></span>.
</p>
</li>
+<li class="listitem">
+ <p>
+ A new statistics counter has been added to track prefetch
+ queries. [RT #45847]
+ </p>
+ </li>
+<li class="listitem">
+ <p>
+ The <span class="command"><strong>dnssec-signzone -x</strong></span> flag and the
+ <span class="command"><strong>dnssec-dnskey-kskonly</strong></span> option in
+ <span class="command"><strong>named.conf</strong></span>, which suppress the use of
+ the ZSK when signing DNSKEY records, now also apply to
+ CDNSKEY and CDS records. Thanks to Tony Finch for the
+ contribution. [RT #45689]
+ </p>
+ </li>
</ul></div>
</div>
<dt><span class="term">-x</span></dt>
<dd>
<p>
- Only sign the DNSKEY RRset with key-signing keys, and omit
- signatures from zone-signing keys. (This is similar to the
+ Only sign the DNSKEY, CDNSKEY, and CDS RRsets with
+ key-signing keys, and omit signatures from zone-signing
+ keys. (This is similar to the
<span class="command"><strong>dnssec-dnskey-kskonly yes;</strong></span> zone option in
<span class="command"><strong>named</strong></span>.)
</p>
matching <span class="command"><strong>cookie-secret</strong></span>.
</p>
</li>
+<li class="listitem">
+ <p>
+ A new statistics counter has been added to track prefetch
+ queries. [RT #45847]
+ </p>
+ </li>
+<li class="listitem">
+ <p>
+ The <span class="command"><strong>dnssec-signzone -x</strong></span> flag and the
+ <span class="command"><strong>dnssec-dnskey-kskonly</strong></span> option in
+ <span class="command"><strong>named.conf</strong></span>, which suppress the use of
+ the ZSK when signing DNSKEY records, now also apply to
+ CDNSKEY and CDS records. Thanks to Tony Finch for the
+ contribution. [RT #45689]
+ </p>
+ </li>
</ul></div>
</div>