Re: running named built with --enable-native-pkcs11 without HSM provider library

2015-07-31 Thread Tomas Hozza
On 30.07.2015 19:35, Evan Hunt wrote: > On Thu, Jul 30, 2015 at 10:19:49AM -0700, Carl Byington wrote: > > RHEL7/Centos7 now has softhsm v2 available. What about a new pkcs11 > > provider that is just an interface into openssl? > > > > --enable-native-pkcs11 \ > > --with-pkcs11=pkcs11-openssl-s

Re: REQUIRE(rdataset->rdclass == db->rdclass) failed

2015-07-31 Thread Tony Finch
Maria Iano wrote: > > I only have one view for "in"; the reason I am using views is to make > chaos bind queries work for specific client IPs only. You don't want attach-cache in this case: you can make the class CH view authoritative only, and it will not interfere with class IN queries to the c

Re: do not stupidly delete ZSK files

2015-07-31 Thread Tony Finch
David Newman wrote: > On 7/30/15 10:37 AM, Evan Hunt wrote: > > On Thu, Jul 30, 2015 at 10:30:33AM -0700, David Newman wrote: > >> > >> Hidden primary (not authoritative for this zone): Key still in zone I think what you mean here is that the hidden primary is not advertised in the zone's NS RRse

Re: do not stupidly delete ZSK files

2015-07-31 Thread David Newman
On 7/31/15 4:33 AM, Tony Finch wrote: > David Newman wrote: >> On 7/30/15 10:37 AM, Evan Hunt wrote: >>> On Thu, Jul 30, 2015 at 10:30:33AM -0700, David Newman wrote: Hidden primary (not authoritative for this zone): Key still in zone > > I think what you mean here is that the hidden pr