In 9.18, 'inline-signing yes;' must also be configured explicitly for
zones using dnssec-policy without a configured 'allow-update' or
'update-policy'.
zone longer-lifetime {
type primary;
file "longer-lifetime.db";
+ inline-signing yes;
dnssec-policy short-lifetime;
};
zone shorter-lifetime {
type primary;
file "shorter-lifetime.db";
+ inline-signing yes;
dnssec-policy long-lifetime;
};
zone limit-lifetime {
type primary;
file "limit-lifetime.db";
+ inline-signing yes;
dnssec-policy unlimited-lifetime;
};
zone unlimit-lifetime {
type primary;
file "unlimit-lifetime.db";
+ inline-signing yes;
dnssec-policy short-lifetime;
};
zone longer-lifetime {
type primary;
file "longer-lifetime.db";
+ inline-signing yes;
dnssec-policy long-lifetime;
};
zone shorter-lifetime {
type primary;
file "shorter-lifetime.db";
+ inline-signing yes;
dnssec-policy short-lifetime;
};
zone limit-lifetime {
type primary;
file "limit-lifetime.db";
+ inline-signing yes;
dnssec-policy short-lifetime;
};
zone unlimit-lifetime {
type primary;
file "unlimit-lifetime.db";
+ inline-signing yes;
dnssec-policy unlimited-lifetime;
};