Managing DNSSEC Trust Anchors in the Lua Configuration

The DNSSEC Trust Anchors and Negative Trust Anchors must be stored in the Lua Configuration file. See the DNSSEC in the PowerDNS Recursor for all information about DNSSEC in the PowerDNS Recursor. This page only documents the Lua functions for DNSSEC configuration

addDS(name, dscontent)

Adds a DS record (Trust Anchor) to the configuration

Parameters:
  • name (str) – The name in the DNS tree from where this Trust Anchor should be used
  • dsrecord (str) – The DS Record content associated with name
addNTA(name[, reason])

Adds a Negative Trust Anchor for name to the configuration. Please read Negative Trust Anchors for operational information on NTAs.

Parameters:
  • name (str) – The name in the DNS tree from where this NTA should be used
  • reason (str) – An optional comment to add to this NTA