Documentation clarifications on dnssec-policy and dynamic zones
Section 4.2.28 (dnssec-policy Statement Definition and Usage) should probably mention that inline-signing is implicitly enabled unless the zone is a dynamic zone, and should also reference (i.e. link to) section 4.2.36.4? Section 4.2.36.4 (Dynamic Update Policies) should outline the consequences (of using dynamic zones) on zone file management, including:
The zone file can no longer be manually updated while named is running, without first performing rndc freeze and then after editing performing rndc thaw. Comments and formatting in the zone file will be lost when dynamic updates (including DNSSEC signing) occur?