Re: [Opendnssec-user] ods-enforcerd in error loop required manual ods-ksmutil hacking to get unstuck :(

2014-09-23 Thread Matthijs Mekking
On 23-09-14 16:19, Paul Wouters wrote: On Tue, 23 Sep 2014, Matthijs Mekking wrote: And for unknown reasons it is now only creating a single RRSIG record for the DNSKEY set (by the KSK) and none of the RRSIG records by the ZSK, turning these 4 zones into bogus :( Deleting all files in /var/ope

Re: [Opendnssec-user] ods-signerd crashes - prob partially my fault

2014-09-23 Thread Rickard Bellgrim
On Fri, Sep 19, 2014 at 9:49 PM, Paul Wouters wrote: > [root@ns0 log]# ls -l /var/softhsm/slot0.db > -rw-rw-r--. 1 root nsd 329728 Sep 14 10:09 /var/softhsm/slot0.db > What user and group is ods-signer dropping to according to conf.xml? // Rickard ___

Re: [Opendnssec-user] ods-enforcerd in error loop required manual ods-ksmutil hacking to get unstuck :(

2014-09-23 Thread Rickard Bellgrim
On Mon, Sep 22, 2014 at 4:44 PM, Paul Wouters wrote: > > It is possible that testing with softhsm-2 and then reverting to > softhsm-1 caused these to happen, if these keys were generated during > the 2 days of running softhsm-v2. > It could be that the keys were generated during that time. Do yo

Re: [Opendnssec-user] ods-enforcerd in error loop required manual ods-ksmutil hacking to get unstuck :(

2014-09-23 Thread Paul Wouters
On Tue, 23 Sep 2014, Matthijs Mekking wrote: And for unknown reasons it is now only creating a single RRSIG record for the DNSKEY set (by the KSK) and none of the RRSIG records by the ZSK, turning these 4 zones into bogus :( Deleting all files in /var/opendnssec/tmp/ and /var/opendnssec/signed/

Re: [Opendnssec-user] two very different softhsm 2.0.0b1 tar balls?

2014-09-23 Thread Jakob Schlyter
On 23 sep 2014, at 04:31, Paul Wouters wrote: > https://github.com/opendnssec/SoftHSMv2/archive/2.0.0b1.tar.gz this one is auto-generated by github, please ignore. > http://dist.opendnssec.org/source/testing/softhsm-2.0.0b1.tar.gz this is the official release tar ball. jakob