ADC

Configure DNSSEC when the NetScaler is authoritative for a zone

When the NetScaler is authoritative for a given zone, all the resource records in the zone are configured on the ADC. To sign the authoritative zone, you must create the zone signing and the key signing keys for the zone, add the keys to the ADC, and then sign the zone. For more information, see:

If any GSLB domains configured on the ADC belong to the zone being signed, the GSLB domain names are signed along with the other records that belong to the zone.

After you sign a zone, responses to requests from DNSSEC-aware clients include the RRSIG resource records along with the requested resource records. DNSSEC must be enabled on the ADC. For more information about enabling DNSSEC, see Enable and disable DNSSEC.

Finally, after you configure DNSSEC for the authoritative zone, you must save the NetScaler configuration.

Configure DNSSEC when the NetScaler is authoritative for a zone