<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Arial" size="2">
<div>-----BEGIN PGP SIGNED MESSAGE-----</div>
<div>Hash: SHA256</div>
<div> </div>
<div>> Trying to sign a copy of ".FR" (1.5 Mdomains, NSEC3, opt-out, two DS</div>
<div>> added), the auditor runs for a long time (see my other messages) then</div>
<div>> stops and I find no /var/opendnssec/signed/fr (I can sign smaller</div>
<div>> zones fine). In /var/opendnssec/tmp, I find only:</div>
<div> </div>
<div>We have never tried to run the auditor on such a large zone. Not even with the .SE zone. The auditor checks everything from its requirements. A future version can be configured to perform a subset of these tests. But for now, you have to disable the auditor
for a very large zone.</div>
<div> </div>
<div>1.</div>
<div>Remove the audit tag from your policy in the kasp.xml</div>
<div> </div>
<div>2.</div>
<div>Update the system</div>
<div>"ods-ksmutil update"</div>
<div> </div>
<div>3.</div>
<div>Wait for the ods-enforcerd to generate a new configuration. It does that with the period specified in the conf.xml (<Enforcer><Interval>) Or if you want it to do it right away:</div>
<div>killall -HUP ods-enforcerd</div>
<div>(don’t forget the -HUP)</div>
<div> </div>
<div>4.</div>
<div>Now will the signer have a new zone configuration to sign with.</div>
<div> </div>
<div>// Rickard</div>
<div> </div>
<div>-----BEGIN PGP SIGNATURE-----</div>
<div>Version: 9.8.3 (Build 4028)</div>
<div>Charset: utf-8</div>
<div> </div>
<div>wsBVAwUBSuhlfOCjgaNTdVjaAQhgcAf+JufJ/DPU4evdN+j1LojYfx9vvDmaPj5O</div>
<div>Ex/c/tSfEXySJpHKWiYss7zaJo49JblHOlYAxmAv+ksjhml6A7pRHWH/JtY9flD3</div>
<div>X0DrTSDH/tJhIDlrtS5JgedM3QUJBf4r/c2rgXRIXLtoOTPA1106qmxfB+455wVY</div>
<div>KvU4Nt5E7dWTWRQnSlndDJKXjH1UH59iiSCysJP2n9wDaXDDUCR8p0C499Sz49EX</div>
<div>DnYEb8Ua4zJ+Q9Nt3xHnYz35/nOIGnJu7zgUcvdECDeerT46+FXjLCmiecoBPjJP</div>
<div>wpyxrLQ7lTQ7VLT+IWm7C3cDQrB52+AV/RIEfHETPIoGEZHU/Uk4dw==</div>
<div>=XYwd</div>
<div>-----END PGP SIGNATURE-----</div>
<div> </div>
<div> </div>
</font>
</body>
</html>