Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Rick van Rein
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, > > But, hum, how can a tool like validns know things the auditor did, > > Just parse the signconf.xml You'd be checking up on a tool, but at the same time trusing it? My response would've been "just look in authoritative DNS for its current st

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Miek Gieben
[ Quoting at 12:19 on Mar 8 in "Re: [Opendnssec-user..." ] > |> directory and call rndc. * If it fails send an e-mail. > | > | This is how we (the developers) envisioned this to be done now that the > | auditor has left the building. > | > | jakob > > But, hum, how can a tool like validns

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Mathieu Arnold
+--On 8 mars 2012 11:47:51 +0100 Jakob Schlyter wrote: | On 8 mar 2012, at 11:44, Scott Armitage wrote: | |> We haven't implemented anything, but the way I would do it would be: |> |> * Have the signer put the files into an intermediate directory e.g. |> /unchecked * Get ODS to call a perl scr

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Einar Bjarni Halldórsson
> On 8 mar 2012, at 11:44, Scott Armitage wrote: > >> We haven't implemented anything, but the way I would do it would be: >> >> * Have the signer put the files into an intermediate directory e.g. >> /unchecked >> * Get ODS to call a perl script using the NotifyCommand in conf.xml >> * In the

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Jakob Schlyter
On 8 mar 2012, at 11:44, Scott Armitage wrote: > We haven't implemented anything, but the way I would do it would be: > > * Have the signer put the files into an intermediate directory e.g. /unchecked > * Get ODS to call a perl script using the NotifyCommand in conf.xml > * In the perl script c

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Scott Armitage
On 8 Mar 2012, at 10:25, Einar Bjarni Halldórsson wrote: > Hi, > > After getting hit by https://issues.opendnssec.org/browse/OPENDNSSEC-216 we > upgraded ods to SVN r6202. For us that means no more auditor. We're looking > at alternatives, like validns, but we're unsure of how to integrate act

Re: [Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Miek Gieben
[ Quoting at 10:25 on Mar 8 in "[Opendnssec-user] Re..." ] > Hi, > > After getting hit by https://issues.opendnssec.org/browse/OPENDNSSEC-216 we > upgraded ods to SVN r6202. For us that means no more auditor. We're looking at > alternatives, like validns, but we're unsure of how to integrate act

[Opendnssec-user] Replacement for auditor in 1.4.0

2012-03-08 Thread Einar Bjarni Halldórsson
Hi, After getting hit by https://issues.opendnssec.org/browse/OPENDNSSEC-216 we upgraded ods to SVN r6202. For us that means no more auditor. We're looking at alternatives, like validns, but we're unsure of how to integrate active monitoring into our setup. The zone file is updated every 20 min