[Opendnssec-user] Set a very low TTL for a label

Ondřej Caletka Ondrej.Caletka at cesnet.cz
Thu Dec 19 09:15:36 UTC 2013


I'm using OpenDNSSEC 1.3.2. I'm trying to set a very low TTL (like 60)
for one label in the zone (the IP address is going to change and I want
to minimize downtime). I noticed, that in the signed file, all TTLs are
clamped to the SOA minimum value set in KASP. When I lowered that value,
all RRSIG and NSEC3 records in the zone were set to this lowest TTL.

Is it somehow possible to lower TTL of only one label (and probably the
nearest neighbours in the NSEC3 chain) without affecting all the
signatures in the zone?


Ondřej Caletka,

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5563 bytes
Desc: Elektronicky podpis S/MIME
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20131219/b6d53b0e/attachment.bin>

More information about the Opendnssec-user mailing list