Re: Problems with the Deletion of Retired Keys in DNSSEC

2024-11-08 Thread Matthijs Mekking
Hi, To automate this you need to configure parental-agents. From 9.20.0 you can use the new 'checkds' option to automatically populate parental-agents. Best regards, Matthijs On 11/8/24 12:23, Τάσος Λολότσης wrote: Hello Thank you very much for the reply. I thought this was happening au

Re: Problems with the Deletion of Retired Keys in DNSSEC

2024-11-08 Thread Τάσος Λολότσης
Hello Thank you very much for the reply. I thought this was happening automatically because I used dnssec-policy. If it’s not happening, is there something else that can help me automate this process by withdrawing the key ? On Fri, Nov 8, 2024 at 12:58 AM Crist Clark wrote: > You need to tell

Re: Problems with the Deletion of Retired Keys in DNSSEC

2024-11-07 Thread Crist Clark
You need to tell BIND the DS is gone from the parent. See the usage for, rndc dnssec -checkds withdrawn On Thu, Nov 7, 2024 at 12:04 PM Τάσος Λολότσης wrote: > Hello all, > > I’m currently facing an issue with DNSSEC key management in BIND and > would appreciate any insights or experiences yo

Problems with the Deletion of Retired Keys in DNSSEC

2024-11-07 Thread Τάσος Λολότσης
Hello all, I’m currently facing an issue with DNSSEC key management in BIND and would appreciate any insights or experiences you might have. I have configured a DNSSEC policy for my domain with the following settings: keys { csk key-directory lifetime P365D algorithm ecdsa256; }; // Key ti