[dns-operations] Diffing tools for zones?

Paul Hoffman phoffman at proper.com
Mon Aug 2 19:09:19 UTC 2010

Greetings. I used to be able to do a reasonably sane check for changed between two versions of the root zone with 'diff'. Now that the root is signed, that all goes to hell.

Are there any reasonable tools that know how to look for differences in two versions of a modern zone? By "reasonable" I mean "ignores changes in NSEC and NSEC3 records and other things that are normal in the daily operation of a signed zone".

--Paul Hoffman

More information about the dns-operations mailing list