Re: inline-signing a zone that exists in two views

2017-05-08 Thread Gordon Messmer
On 05/08/2017 03:26 AM, Tony Finch wrote: Gordon Messmer wrote: I have a zone that I'd like to serve in two different views, with dnssec in both views. You can't have zones in different views (which sre by implication different zones, or different versions of the same zone) pointing to the sa

Re: error when removing expired key files

2017-05-08 Thread Gordon Messmer
On 05/08/2017 03:22 AM, Tony Finch wrote: Gordon Messmer wrote: After new keys are introduced, and after the old key has expired, Wait right there! dnssec-settimes has two times that are usually relevant to the old key when rolling keys: the retire time and the delete time. (There's also a re

Re: inline-signing a zone that exists in two views

2017-05-08 Thread Tony Finch
Gordon Messmer wrote: > I have a zone that I'd like to serve in two different views, with dnssec in > both views. You can't have zones in different views (which sre by implication different zones, or different versions of the same zone) pointing to the same files on disk, because updates to one

Re: error when removing expired key files

2017-05-08 Thread Tony Finch
Gordon Messmer wrote: > > After new keys are introduced, and after the old key has expired, Wait right there! dnssec-settimes has two times that are usually relevant to the old key when rolling keys: the retire time and the delete time. (There's also a revocation time but we don't need to worry

dyndb regression: bind fails to build --without-dlopen

2017-05-08 Thread Peter Volkov
Hello. bind 9.10.x and 9.11.x fails to build if ./configure'ed --without-dlopen[1]: libtool: compile: x86_64-pc-linux-gnu-gcc -I/var/tmp/portage/net-dns/ bind-9.11.0_p1/work/bind-9.11.0-P1 -I../.. -I./include -I../dns/include -I/var/tmp/portage/net-dns/bind-9.11.0_p1/work/bind-9.11.0-P1/lib/dns/