Re: How do I reset a DNSSEC zone ?

2017-08-20 Thread Pierre Couderc
On 08/20/2017 03:21 PM, /dev/rob0 wrote: On Sun, Aug 20, 2017 at 01:21:21PM +0200, Pierre Couderc wrote: how to get rid of this message ? If named is configured to sign the zone, it will continue looking for your zone keys. Thank you, your answer is what I needed. I have stop signing then

Re: How do I reset a DNSSEC zone ?

2017-08-20 Thread /dev/rob0
On Sun, Aug 20, 2017 at 01:21:21PM +0200, Pierre Couderc wrote: > I did do it roughly on a test zone, by erasing the key and > erasing all zone.jnl, zone.signed, etc > > hoping come back to the initial status. But I get the message : > > dns_dnssec_keylistfromrdataset: error reading private key f

Re: How do I reset a DNSSEC zone ?

2017-08-20 Thread Alberto Colosi
is like is missing the file referenced in log SHA-1 RSA signing is obsolete and banned from NIST and ENRISA is a CVE or should if I remember ell All CA only use SHA-2 no more version 1 as said before. SHA-2 and 2048 or greater yor problem is like file permission or file is missing _

How do I reset a DNSSEC zone ?

2017-08-20 Thread Pierre Couderc
I did do it roughly on a test zone, by erasing the key and erasing all zone.jnl, zone.signed, etc hoping come back to the initial status. But I get the message : dns_dnssec_keylistfromrdataset: error reading private key file zone/RSASHA1/21477: file not found That is normal as I have erased