Now there is a similar, though slightly different problem with another zone
kvi-cart.rug.nl.
The signer responded with servfail when requested for the SOA record, or for
zone transfers for this zone.
In the systlog, there where a log of messages like:
May 16 20:32:42 dns ods-signerd: [axfr] zon
Hi,
In the zonelist.xml I only specify the location of the adapter config file,
not the location of the unsigned zones.
(The location for the unsigned zones is specified if no zone transfers are
used for the input zones.)
Also, in the adapter config, I do not specify a location of the incoming
Hi,
> Although I found a work-around already, I looked in the
> /var/opendnssec/unsigned directory. This directory is completely empty.
> Apparently, the received zones are stored somewhere else.
The actual directory is configured in /etc/opendnssec (usually).
> In the /var/opendnssec/tmp dire
Hi Rick,
Although I found a work-around already, I looked in the
/var/opendnssec/unsigned directory. This directory is completely empty.
Apparently, the received zones are stored somewhere else. In the
/var/opendnssec/tmp directory there are some rug.nl* files (among which a
rug.nl.axfr), but
Hello,
I'm looking into OpenDNSSEC v 1.4.5 configuration files and I can't see any
hooks for user scripts in Enforcer's configuration.
I would like to run my own script every time a new key is generated or
existing key is deleted (or even better - after any state change).
What mechanism wou
Thanks Sion,
The information was very useful for my ;-)
However, something strange is happening with the rollover times:
KSK active2014-05-20 17:05:53 (retire)
KSK publish 2014-05-19 10:47:20 (ready)
ZSK retire2014-05-18 16:02:20 (dead)
ZSK act