Hi Fred,
On 09-08-16 17:14, Fred.Zwarts wrote:
There are active and ready keys:
# ods-enforcer key list --zone KVI.nl
Keys:
Zone: Keytype: State: Date of next transition:
KVI.nl KSK retire 2016-08-12 16:33:10
KVI.nl ZSK active 2016-08-12 16:33:10
KVI.nl ZSK ready 2016-08-12 16:33:10
KVI.nl KSK active 2016-08-12 16:33:10
key list completed in 0 seconds.
# ods-enforcer key export --zone KVI.nl
key export completed in 0 seconds.
I'll rephrase Hoda's words to make it a bit more accurate: key export
prints the keys that need to be submitted to the parent zone and are not
ds-seen yet. So if it would say "waiting for ds-seen" your key export
would also show you the DNSKEY record.
try:
ods-enforcer key export --zone KVI.nl -t KSK
//Yuri
_______________________________________________
Opendnssec-user mailing list
Opendnssec-user@lists.opendnssec.org
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user