With inline signing DNSSEC records (other than DS) are modified by other paths than using UPDATE. I would be using these mechanisms instead of UPDATE even with normal signed zones. dnssec-settime and dnssec-keygen -P sync date/offset Sets the date on which CDS and CDNSKEY records that match this key are to be published to the zone. -D sync date/offset Sets the date on which the CDS and CDNSKEY records that match this key are to be deleted. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: marka@isc.org