Re: Switching to a different dnssec-policy broke my zone.

2023-11-24 Thread Björn Persson
Matthijs Mekking wrote: > Please file a bug report: https://gitlab.isc.org/isc-projects/bind9/-/issues/4453 Björn Persson pgpEviPQ3dVa_.pgp Description: OpenPGP digital signatur -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list ISC funds the development

Re: Switching to a different dnssec-policy broke my zone.

2023-11-22 Thread Matthijs Mekking
This should be possible. Please file a bug report: https://gitlab.isc.org/isc-projects/bind9/-/issues/new Mention the version used and describe the steps how to reproduce. Best regards, Matthijs On 11/22/23 13:20, Björn Persson wrote: My zone was previously signed with a KSK and a ZSK with

Switching to a different dnssec-policy broke my zone.

2023-11-22 Thread Björn Persson
My zone was previously signed with a KSK and a ZSK with unlimited lifetime. I switched the zone over to a dnssec-policy using CSKs and automatic key rotation. After the DS record was updated, most of the RRSIG records were removed, leaving the zone broken to validating resolvers. Am I not supposed