[Opendnssec-develop] 5000 zones - almost possible

Rickard Bellgrim rickard.bellgrim at iis.se
Thu Nov 12 08:15:07 UTC 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> > * ods-enforcerd has some problems with memory leaks.
>
> I'll look into these as soon as I finish the KSK stuff; realistically
> this
> will be next week.

I suggest that this goes into v1.0.0, since it has to do with the stability of the system.

> > * OpenDNSSEC v1.0.0 cannot be used for signing a large number of
> zones.
>
> I have done no optimisation for large numbers of zones. A very simple
> one
> for shared keys would be to write out essentially the same file (just
> tweak
> it) for all zones. (Note that it is also doing all the timing
> calculations
> again.) Also there are no indexes on the tables, this should help.

I suggest that this goes into v1.1.0, since we currently are ok with handling a few zones.

> The real fun comes when you do not share keys.

And this needs some rework of the architecture => v2.0.0


-----BEGIN PGP SIGNATURE-----
Version: 9.8.3 (Build 4028)
Charset: utf-8

wsBVAwUBSvvEC+CjgaNTdVjaAQgeBwf9FvuM8bqVZ5HtU2hNEYtOyJExzqK9sABq
TTqmUlExJT15HZG8io+d5SKvrUSSTQkAsWSvtPi7XV7dZ7QssmJQzDfiRSrjDNGP
YRbyKKcrQio/togdY7ARWk6TStNpkyTzzbKO0E8FmLsTLTOfDmx9OX50RL1nQ39X
Nl5dxHrjocJ815gSX+V6pnHNKZ+f94WbCutC3VBjMEdKeYAYErd5YyGo2Xwzxu9n
t6KowCX+0FDhHTrMyttMkfoanKpFE6/kg6d3my5I2RqSAam9GsgC7jLHC7yCCp0b
A6x1ZxLL3ZkI62yLhUr9LtdOXnjzrxza7TpVHrMQptQOAo+nO9wELA==
=pFiT
-----END PGP SIGNATURE-----


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opendnssec.org/pipermail/opendnssec-develop/attachments/20091112/19a0189b/attachment.htm>


More information about the Opendnssec-develop mailing list