diff --git a/bin/rndc/rndc.docbook b/bin/rndc/rndc.docbook index a78f35804a..1ab0417274 100644 --- a/bin/rndc/rndc.docbook +++ b/bin/rndc/rndc.docbook @@ -606,13 +606,13 @@ Sets a DNSSEC negative trust anchor (NTA) for , with a lifetime of . The default lifetime is - configured in named.conf via the - , and defaults to + configured in named.conf via the + option, and defaults to one hour. The lifetime cannot exceed one week. A negative trust anchor selectively disables - DNSSEC validation for zones that known to be + DNSSEC validation for zones that are known to be failing because of misconfiguration rather than an attack. When data to be validated is at or below an active NTA (and above any other