Re: understanding keymgr handling of KSK

2022-05-09 Thread Matthijs Mekking
Hi, On 09-05-2022 10:16, Bjørn Mork wrote: Michael Richardson via bind-users writes: 4) I don't understand the difference between "auto-dnssec maintain;" and "dnssec-policy default" (given that I haven't overridden anything). I believe the only difference is that the latter will track

Re: understanding keymgr handling of KSK

2022-05-09 Thread Bjørn Mork
Michael Richardson via bind-users writes: > I have moved from dnssec-tools to having bind9 do all the management itself. > There are a couple of things that I don't understand, and I find that the > FAQs and howtos I've read are rather too introductory for me. > I have been signing my zones since

Re: understanding keymgr handling of KSK

2022-05-08 Thread Michael Richardson via bind-users
I found this message: May 8 16:41:18 tilapia named[1268]: zone ox.org/IN: zone_rekey:dns_dnssec_keymgr failed: error occurred writing key to disk It would be great if it could tell me the file name that failed to write, and ideally what the error was (EPERM is my guess, but there could also be

understanding keymgr handling of KSK

2022-05-08 Thread Michael Richardson via bind-users
I have moved from dnssec-tools to having bind9 do all the management itself. There are a couple of things that I don't understand, and I find that the FAQs and howtos I've read are rather too introductory for me. I have been signing my zones since around 2004... I will attempt to blog some of my e