LPI 303-200 Question Answer
How does TSIG authenticate name servers in order to perform secured zone transfers?
Both servers mutually verify their X509 certificates.
Both servers use a secret key that is shared between the servers.
Both servers verify appropriate DANE records for the labels of the NS records used to delegate the transferred zone.
Both servers use DNSSEC to mutually verify that they are authoritative for the transferred zone.
TESTED 15 Jul 2025
Copyright © 2014-2025 ACE4Sure. All Rights Reserved