2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-29 05:28:00 +00:00

Improve parental-agents definition in ARM

"A parental agent is the entity that is allowed to change a zone's
delegation information" is untrue, because it is possible to use some
hidden server or a validating resolver.

Also the new text makes it more clear that named sends DS queries to
these servers.
This commit is contained in:
Matthijs Mekking 2024-01-15 09:17:01 +01:00
parent a863450695
commit 604f8e7797

View File

@ -1060,10 +1060,10 @@ responses such as NXDOMAIN.
:any:`parental-agents` Block Definition and Usage
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
:any:`parental-agents` lists allow for a common set of parental agents to be easily
used by multiple primary and secondary zones.
A parental agent is the entity that is allowed to
change a zone's delegation information (defined in :rfc:`7344`).
:any:`parental-agents` lists allow for a common set of parental agents to be
easily used by multiple primary and secondary zones. A "parental agent" is a
trusted DNS server that is queried to check if DS records for a given zones
are up-to-date.
:any:`primaries` Block Grammar
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~