|
With no 'in-built' auditing function in OpenDNSSEC one option is to post process the zone. It is possible to do this using the NotifyCommand in conf.xml. An example workflow would be:
An alternative solution is that the signed zones from OpenDNSSEC may be transfered to a hidden master and a validation tool may be run before the zones are distributed to the slave servers.
http://www.nlnetlabs.nl/projects/credns/