[Opendnssec-develop] Enforcer NG testing

Matthijs Mekking matthijs at NLnetLabs.nl
Tue Aug 30 13:05:59 UTC 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 08/30/2011 09:58 AM, Rickard Bellgrim wrote:
> Hi
> Signer configuration:
> - I previously said that the KSK was marked as active, but the key
> list said not. Ignore this, I think it is the correct behaviour. The
> KSK tag is set when the RRSIGDNSKEY is rumoured or omnipresent, right?

This sounds correct, as in these two stages the KSK is being used for
signing.

> key list:
> - A KSK with DS, DNSKEY, and RRSIGDNSKEY marked as omnipresent does
> not get marked as active

What do you mean here with 'get marked as active'?

Best regards,
  Matthijs
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJOXOA3AAoJEA8yVCPsQCW59BoH/RTtTKXIkGU+J+3DFVKU/Osj
z9HjU3ieIvrV1bgRhdbBC8Cqtd5H21lTpA/VyHEEkucnBJjwTZF1B48t2pST0ly0
EW1CX8MDdb6AxWWwpceVGpcXVxDYBmqZcEaeX7JiHrPZjrwKv4LMq6ANJ6KLoyps
2lJOOv8vah0Ofb66OUemO12XGUrXmKy+R2b2ew47IefdUN7dZofCsPsVkDc5ZaFO
vhv9KEXIuWPpz0OEuAitYlCXPlCHFWmkm6Pbx2Yn5xboTG2ovdXcNWBY9p+JxcBt
ABa7bZZvRFdnhzMShrZPwlsYMCgMKWbTJZo9SN5/EuDSO8tEAjGC7s0yfft7HU0=
=OANy
-----END PGP SIGNATURE-----



More information about the Opendnssec-develop mailing list