From owner-dnssec-trac at kirei.se Sun May 1 18:25:41 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Sun, 01 May 2011 18:25:41 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #234: Accumulating Wealth through Penny Stock Trading Message-ID: <047.b3aabff19fde2c56ae15d4f19f99237e@kirei.se> #234: Accumulating Wealth through Penny Stock Trading ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Accumulating Wealth through Penny Stock Trading The penny stock is really a stock, which costs you $5 as well as less than that. It is almost always traded outside the main top markets. Since this kind of stock is actually independently dealt with and it is reduced price, it is an excellent means for beginner traders to get knowledge of the stock market, additionally, to knowing the in depth working of trading counters. Trading within penny stock is definitely one of the best options available for people, who wish to help to make wealth and be rich. They need to gather facts as well as tips, that assist all of them for making cash via trading in this stock. For, individuals may help to make or lose their cash in to the market. Information beneath may show you in this moneymaking endeavor. Firstly, it is advisable that you know well before actually involving in any stock trade. Make sure that you never begin purchasing stocks simply because somebody said it's a good idea. Be prepared for earning money, however before which very first do your homework for sure. Make use of resources which help a person in avoiding financial reduction whilst investing in [http://www.pennystockstrategy.com penny stocks]. Secondly, think about subscribing to a financial newspaper, as it can help you significantly within understanding details concerning stocks. Make the most of this newspaper support, if you're serious about purchasing stocks for money. This may enable you within identifying the good sectors from time to time as well as show you upon keeping away from particular risk- prone sectors. Bear in mind that timing is, in order to make prosperity via [http://www.pennystockstrategy.com penny stock] trading. Seem wise as well as consider your decision sensibly. Make sure that you don't whack your hard earned money by looking into making any kind of bad transfer as well as for this understand the stock marketplace fully and about it's working pattern. After educating a lot more than this particular, you might after that get a bigger danger. Lastly, know that making wealth through [http://www.pennystockstrategy.com trading penny stocks] isn't a difficult task. Individuals have to speak to any seasoned expert earlier than beginning, so that such experts enable them to during the method. Many people, who're wanting to associated with learning how you can industry quite often begin with penny stock. They may not really know that this kind of stocks are far more harmful compared to blue potato chips. Therefore, in your endeavor of creating wealth via trading in stocks, have better knowledge of the marketplace, because they are dangers involved with this. Once you are acquainted with the actual particulars of trading, go ahead with it. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Sun May 1 18:53:08 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Sun, 01 May 2011 18:53:08 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #235: Online fundraising brand new technique to increase funds Message-ID: <047.41dd80541f5a9a9cd2827a1f2f96f074@kirei.se> #235: Online fundraising brand new technique to increase funds ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Online fundraising brand new technique to increase funds There are lots of ways to raise funds. [http://www.give2gether.com Online fundraising] experienced acquired impetus in these years. Increasing cash with using Internet is a profitable method for increasing money. It is probably the most efficient ways, which will give you achievement. It is essential in order to plan precisely and also have fixed schedule. You have to make use of various different methods making people think that their are being employed for a beneficial purpose. You need to keep appealing provides, use different ways, as well as experiment. Make individuals believe that you do the noble trigger and they too should join you and also serve the actual society. There are few various encounters in [http://www.onlinefundraisings.com online fundraising]. You may use the online online auctions and can increase money for that organization or even charitable organisation you prefer the majority of. You can plan and implement a focus on a list of emails to obtain donations. If you are very new to this field then, you can test the different web sites that offer several options with regard to charity. You can try that old technique. It is very simple and best. The actual online shops provide choices that while make payment on total expenses, if the client pays little amount it will instantly go to the charitable organisation. Lots of people such as this technique and it is a great way to increase money. If you think that, you can gather much more funds through [http://www.give2gether.com fundraising online] task then you have to discover the web sites, which are popular for online auctions. Choose the one, that has the majority of traffic, and ensure that it's user friendly. You can also try through collecting the things in the nearby vendor who'll market you exact same item within relatively less price and then sell on all of them in the public sale. Let people know the profit quantity goes towards the charitable organisation. This process will help you increase a substantial amount. You can also enlist in the providers from the e-mail company and send all of them the e-mail messages who will send to the unique list of subscribers who've contributed in the past. Such types of methods works nicely, if you are planning to do the main things for that creatures or nature. All you've got to make sure is your postal mail does not come in the actual spam list. Sometimes this method can be expensive; therefor it is necessary if you are planning a budget to satisfy all of the expenses. And you can easily increase money for different organisations. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Mon May 2 09:57:32 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Mon, 02 May 2011 09:57:32 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #231: Configure fails on mysql_version substitution In-Reply-To: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> References: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> Message-ID: <070.177ffe8ed0ec047030a9d0628040afba@kirei.se> #231: Configure fails on mysql_version substitution ------------------------------+--------------------------------------------- Reporter: Olaf@? | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Resolution: Keywords: configure | ------------------------------+--------------------------------------------- Comment (by anonymous): Yes it does.. but I do not understand why: How does a string like '4.1.2' evaluate in numeric context: [4.1.2 -le 4 ] I figured the regex is there to isolate the main version number before the evaluation. ??? --Olaf -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Mon May 2 14:47:45 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Mon, 02 May 2011 14:47:45 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #230: CNAME RR and DHCID RR not in signed zone In-Reply-To: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> References: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> Message-ID: <072.0f5e888965965fe06813781da8afa2dc@kirei.se> #230: CNAME RR and DHCID RR not in signed zone --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: matthijs Type: defect | Status: accepted Priority: minor | Component: Unknown Version: 1.2.1 | Resolution: Keywords: | --------------------------------+------------------------------------------- Comment (by Nick van den Heuvel): It also works for me now. I changed the zonefile and I now get a correct signed zonefile with 8 RRSIGS. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Tue May 3 07:42:06 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Tue, 03 May 2011 07:42:06 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #230: CNAME RR and DHCID RR not in signed zone In-Reply-To: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> References: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> Message-ID: <072.8512c2911606a6c7a3f190bb8210b959@kirei.se> #230: CNAME RR and DHCID RR not in signed zone --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: matthijs Type: defect | Status: accepted Priority: minor | Component: Unknown Version: 1.2.1 | Resolution: Keywords: | --------------------------------+------------------------------------------- Comment (by matthijs): That's good to hear. Do you by any chance have the cause of this issue and how you resolved it? What did you change in the zonefile? -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Tue May 3 07:42:24 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Tue, 03 May 2011 07:42:24 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #230: CNAME RR and DHCID RR not in signed zone In-Reply-To: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> References: <057.a20ecf2e53495bb9118a9180d537a643@kirei.se> Message-ID: <072.f8bd37044285442a266052c0b84e620e@kirei.se> #230: CNAME RR and DHCID RR not in signed zone --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: matthijs Type: defect | Status: closed Priority: minor | Component: Unknown Version: 1.2.1 | Resolution: invalid Keywords: | --------------------------------+------------------------------------------- Changes (by matthijs): * status: accepted => closed * resolution: => invalid -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 4 14:36:10 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 04 May 2011 14:36:10 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #236: Use of algorithm 6 gives an error Message-ID: <057.ed176d33442dca507e87526ee9e38b5d@kirei.se> #236: Use of algorithm 6 gives an error --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: jakob Type: defect | Status: new Priority: minor | Component: libhsm Version: 1.2.1 | Keywords: --------------------------------+------------------------------------------- Test steps: Sign a zone with KSK and ZSK algorithm 6, key length 2048 Expected result: Zone succesfully signed. Observerd result: Zone not signed, error message in syslog: "ods-enforcerd: Key algorithm 6 unsupported by libhsm, exiting..." -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Thu May 5 10:01:31 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 05 May 2011 10:01:31 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #233: More backup KSK's created tha configured in kasp.xml In-Reply-To: <057.ecee007325657a483bfcc1bcc163edfa@kirei.se> References: <057.ecee007325657a483bfcc1bcc163edfa@kirei.se> Message-ID: <072.c86b5751456d8334998f02fc7946ad45@kirei.se> #233: More backup KSK's created tha configured in kasp.xml --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: sion Type: defect | Status: assigned Priority: minor | Component: SoftHSM Version: 1.2.1 | Resolution: Keywords: | --------------------------------+------------------------------------------- Comment (by Nick van den Heuvel): KSK lifetime was PT1S. Which caused the enormous pile of keys. Changed the lifetime to P1D, and the testcase works now. This finding can be closed. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Thu May 5 11:54:15 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 05 May 2011 11:54:15 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #233: More backup KSK's created tha configured in kasp.xml In-Reply-To: <057.ecee007325657a483bfcc1bcc163edfa@kirei.se> References: <057.ecee007325657a483bfcc1bcc163edfa@kirei.se> Message-ID: <072.d7d9ccf471826ab4a90b99c99540fc4e@kirei.se> #233: More backup KSK's created tha configured in kasp.xml --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: sion Type: defect | Status: closed Priority: minor | Component: SoftHSM Version: 1.2.1 | Resolution: invalid Keywords: | --------------------------------+------------------------------------------- Changes (by sion): * status: assigned => closed * resolution: => invalid -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 6 06:11:26 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 06:11:26 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #228: Long token name seems to confuse ods-enforcer In-Reply-To: <057.c4d5209d39523bcaec41a8a0c24a28dc@kirei.se> References: <057.c4d5209d39523bcaec41a8a0c24a28dc@kirei.se> Message-ID: <072.b5ee5417f0ff553fc412bbf5f5da54a9@kirei.se> #228: Long token name seems to confuse ods-enforcer --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: sion Type: defect | Status: closed Priority: minor | Component: Enforcer Version: 1.2.1 | Resolution: fixed Keywords: | --------------------------------+------------------------------------------- Changes (by rb): * status: new => closed * resolution: => fixed Comment: I have updated the documentation. http://trac.opendnssec.org/wiki/Signer/Using/Configuration/conf -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 6 06:12:41 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 06:12:41 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #229: When Publish Safety in kaps.xml = '0', kaspcheck validates In-Reply-To: <057.74a8391a83d60b1ea471709eb51c15fc@kirei.se> References: <057.74a8391a83d60b1ea471709eb51c15fc@kirei.se> Message-ID: <072.8764c75ee1b50d0e2214b57e77eb2602@kirei.se> #229: When Publish Safety in kaps.xml = '0', kaspcheck validates --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: rb Type: defect | Status: closed Priority: trivial | Component: Unknown Version: 1.2.1 | Resolution: invalid Keywords: | --------------------------------+------------------------------------------- Changes (by rb): * status: new => closed * resolution: => invalid Comment: Closing this one -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 6 06:14:25 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 06:14:25 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #236: Use of algorithm 6 gives an error In-Reply-To: <057.ed176d33442dca507e87526ee9e38b5d@kirei.se> References: <057.ed176d33442dca507e87526ee9e38b5d@kirei.se> Message-ID: <072.d2c4855242d7a64e265030b649a08f47@kirei.se> #236: Use of algorithm 6 gives an error --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: jakob Type: defect | Status: closed Priority: minor | Component: libhsm Version: 1.2.1 | Resolution: invalid Keywords: | --------------------------------+------------------------------------------- Changes (by rb): * status: new => closed * resolution: => invalid Comment: DSA is not supported -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 6 07:05:23 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 07:05:23 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #231: Configure fails on mysql_version substitution In-Reply-To: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> References: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> Message-ID: <070.5684a21f6ed1e76c393f8989b0b73fda@kirei.se> #231: Configure fails on mysql_version substitution ------------------------------+--------------------------------------------- Reporter: Olaf@? | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Resolution: Keywords: configure | ------------------------------+--------------------------------------------- Comment (by rb): Perhaps this is better? {{{ Index: OpenDNSSEC/m4/acx_mysql.m4 =================================================================== --- OpenDNSSEC/m4/acx_mysql.m4 (revision 5033) +++ OpenDNSSEC/m4/acx_mysql.m4 (working copy) @@ -17,8 +17,9 @@ if test -x "$MYSQL_CONFIG"; then AC_MSG_CHECKING(mysql version) MYSQL_VERSION="`$MYSQL_CONFIG --version`" + MYSQL_VERSION_MAJOR=`echo "$MYSQL_VERSION" | sed -e 's/\..*//'` AC_MSG_RESULT($MYSQL_VERSION) - if test ${MYSQL_VERSION//.*/} -le 4 ; then + if test ${MYSQL_VERSION_MAJOR} -le 4 ; then AC_MSG_ERROR([mysql must be newer than 5.0.0]) fi }}} -- Ticket URL: OpenDNSSEC OpenDNSSEC From rickard at opendnssec.org Fri May 6 07:13:22 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Fri, 6 May 2011 09:13:22 +0200 Subject: [Opendnssec-develop] Meetings in May Message-ID: Hi We never reached an agreement regarding some telephone meeting dates in May. Please mark the dates where you can have a telephone meeting between 14 and 15 CEST. http://www.doodle.com/psgmsbahnk9u7xa6 // Rickard From owner-dnssec-trac at kirei.se Fri May 6 07:37:04 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 07:37:04 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #237: Link Building Services, the Internet and also the SEO Message-ID: <047.260b529b9b47b907cb42165daaf96fea@kirei.se> #237: Link Building Services, the Internet and also the SEO ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Link Building Services, the Internet and also the SEO Today as we all know, the internet offers certainly set the world on fire via it's fantastic programs which will ease and just the actual lives associated with huge numbers of people that rely on the web and it is applications for a number of purposes. The effectiveness from the internet with regards to supplying the information through the web sites will be based a lot on the link trade function; [http://www.guaranteedlinkbuilding.com Link Building] and many this kind of applications which will bring the actual searches nearer to the best information and information through various web sites around the world. The webmasters of the research tools and the SEO understand the vigor from the link exchange and the link building to the core. They know that the actual link building will result in tremendous achievement for that Search engine optimization and the research capabilities performed by the online users all over the world. These really links will help in the measurement from the interest in the web site across the web and it is applications all over the world. These days, google algorithms are efficient plus they utilize the links and also the link factors within arriving at the significance, vigor as well as concern from the web page and its applications. [http://www.guaranteedlinkbuilding.com Link Building Service] will assure the content from the website may refined as well as prepared for the ideal use and will also enable the hyperlinks for use by the search algorithms within the Search engine optimization and therefore they'll lead to linking of the website whenever a research function is conducted through numerous customers around the world. The actual link exchange, the actual link assistance and also the link building just about all work at this content enhancement of the web sites that will consequently result in the greater page ranking from the website and much more sites point towards the web site to create our prime visitors from the online users from just about all parts of the world. This is a massive contribution through the ever improving [http://www.guaranteedlinkbuilding.com Link Building Services] to the internet and its best applications like the Internet search engine Optimisations known as the SEO. The Search engine optimization provides main concern and also the significance towards the Anchor Text of the website which will basically link the actual research procedures from the internet users around the world. The anchor text is actually type of the catalog that will take you through the benefits and knowledge obtainable in your site. Linking from the anchor texts within the research formula will assure the traffic is higher. -- Ticket URL: OpenDNSSEC OpenDNSSEC From jakob at kirei.se Fri May 6 07:59:28 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Fri, 6 May 2011 09:59:28 +0200 Subject: [Opendnssec-develop] Meetings in May In-Reply-To: References: Message-ID: We have already booked the next two teleconfs IIRC. -- Sent from my iPhone, hence this mail might be briefer than normal. 6 maj 2011 kl. 09:13 skrev Rickard Bellgrim : > Hi > > We never reached an agreement regarding some telephone meeting dates in May. > > Please mark the dates where you can have a telephone meeting between > 14 and 15 CEST. > http://www.doodle.com/psgmsbahnk9u7xa6 > > // Rickard > _______________________________________________ > Opendnssec-develop mailing list > Opendnssec-develop at lists.opendnssec.org > https://lists.opendnssec.org/mailman/listinfo/opendnssec-develop > From jakob at kirei.se Fri May 6 08:17:59 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Fri, 6 May 2011 10:17:59 +0200 Subject: [Opendnssec-develop] Meetings in May In-Reply-To: References: Message-ID: Teleconf has been booked for: May 12, 14.00 -- 15.00 CEST May 24, 14.00 -- 15.00 CEST jakob -- Jakob Schlyter Kirei AB - http://www.kirei.se/ From rickard at opendnssec.org Fri May 6 08:23:57 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Fri, 6 May 2011 10:23:57 +0200 Subject: [Opendnssec-develop] Meetings in May In-Reply-To: References: Message-ID: I was not present on the last meeting, so I only have the minutes. "Schedule next two for 12th and 24th May? Might move due to people who were not on the call." So I emailed last week to confirm these dates. I can not attend May 12 and I only got a response from Antoin who pointed out that the CENTR R&D is on the 24th. But we can go with the scheduled dates. On Fri, May 6, 2011 at 10:17 AM, Jakob Schlyter wrote: > Teleconf has been booked for: > > ?May 12, 14.00 -- 15.00 CEST > ?May 24, 14.00 -- 15.00 CEST > > > ? ? ? ?jakob > > -- > Jakob Schlyter > Kirei AB - http://www.kirei.se/ > > From sion at nominet.org.uk Fri May 6 09:08:12 2011 From: sion at nominet.org.uk (Sion Lloyd) Date: Fri, 6 May 2011 09:08:12 +0000 Subject: FW: [Opendnssec-develop] Re: [OpenDNSSEC] #236: Use of algorithm 6 gives an error In-Reply-To: References: Message-ID: For some reason this email ended up in the moderator queue... The overview you link to is at a very low level of detail, and so is current (but describes very little really). Do you need more detail than that? Sion ________________________________________ From: Nick van den Heuvel [nick.vandenheuvel at sidn.nl] Sent: 06 May 2011 09:13 To: 'opendnssec-develop-bounces at lists.opendnssec.org' Subject: FW: [Opendnssec-develop] Re: [OpenDNSSEC] #236: Use of algorithm 6 gives an error Where can I find the latest overview? Is it here?: http://www.opendnssec.org/features/ Can the supported algorithm be specified in kasp.xml documentation on the ODS website? Regards, Nick Nick van den Heuvel Testanalist SIDN | Utrechtseweg 310 | 6812 AR | Postbus 5022 | 6802 EA | ARNHEM T +31 (0)26 352 55 00 | F +31 (0)26 352 55 05 nick.vandenheuvel at sidn.nl | www.sidn.nl -----Original Message----- From: opendnssec-develop-bounces at lists.opendnssec.org [mailto:opendnssec-develop-bounces at lists.opendnssec.org] On Behalf Of OpenDNSSEC Sent: vrijdag 6 mei 2011 8:14 Cc: opendnssec-develop at lists.opendnssec.org Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #236: Use of algorithm 6 gives an error #236: Use of algorithm 6 gives an error --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: jakob Type: defect | Status: closed Priority: minor | Component: libhsm Version: 1.2.1 | Resolution: invalid Keywords: | --------------------------------+------------------------------------------- Changes (by rb): * status: new => closed * resolution: => invalid Comment: DSA is not supported -- Ticket URL: OpenDNSSEC OpenDNSSEC -------------- next part -------------- An embedded and charset-unspecified text was scrubbed... Name: ATT00002.txt URL: From olaf at NLnetLabs.nl Fri May 6 09:17:32 2011 From: olaf at NLnetLabs.nl (Olaf Kolkman) Date: Fri, 6 May 2011 11:17:32 +0200 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #231: Configure fails on mysql_version substitution In-Reply-To: <070.5684a21f6ed1e76c393f8989b0b73fda@kirei.se> References: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> <070.5684a21f6ed1e76c393f8989b0b73fda@kirei.se> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On May 6, 2011, at 9:05 AM, OpenDNSSEC wrote: > #231: Configure fails on mysql_version substitution > ------------------------------+--------------------------------------------- > Reporter: Olaf@? | Owner: rb > Type: defect | Status: new > Priority: major | Component: Unknown > Version: trunk | Resolution: > Keywords: configure | > ------------------------------+--------------------------------------------- > > Comment (by rb): > > Perhaps this is better? > > {{{ > Index: OpenDNSSEC/m4/acx_mysql.m4 > =================================================================== > --- OpenDNSSEC/m4/acx_mysql.m4 (revision 5033) > +++ OpenDNSSEC/m4/acx_mysql.m4 (working copy) > @@ -17,8 +17,9 @@ > if test -x "$MYSQL_CONFIG"; then > AC_MSG_CHECKING(mysql version) > MYSQL_VERSION="`$MYSQL_CONFIG --version`" > + MYSQL_VERSION_MAJOR=`echo "$MYSQL_VERSION" | sed -e > 's/\..*//'` > AC_MSG_RESULT($MYSQL_VERSION) > - if test ${MYSQL_VERSION//.*/} -le 4 ; then > + if test ${MYSQL_VERSION_MAJOR} -le 4 ; then > AC_MSG_ERROR([mysql must be newer than 5.0.0]) > fi > }}} ACK. - --Olaf ________________________________________________________ Olaf M. Kolkman NLnet Labs http://www.nlnetlabs.nl/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: This message is locally signed. Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJNw7yyAAoJEFRqER47aqpkEcQP/047vaVbtzQOab6QG1+aJihT uUoQTZVykFxFE4g2tBBukFIt41wqymPzSZlMZwqD/Yx/PeLG9hIGxyZUFkI2d13i nFiRZuFLIkt1AeZRumRFg3LsS0o2+VDz5hwY5yrMsowY4vk8R3yu6pKP6fhJ7GZg FpfTY1Q2Ic3lQvEeksR/986Wxe3PTjo2chmS2khJ6UgylMdSVsSbAvV3cbDok4eo N2JJM7iM8Ji86fHD4wwkWyHc0dGyx3WFjjBKHsnQyq6pRQv0e3+0E9li3r6BVK3k YvS3VssR5CThCKD3Ii9P4ULcfYa/AsGAM0zZuE+slm+33CmBqR1YnaN/Gtbxan7K +No5z/w9Bep3LVT6QH6CapfrShdDjm8jENHoY525Ip9UcqRS8yfbG8v+r8zSq1Ty Qhok3epKe9k662q8mO71FLEH7Z3VZuHxsNs3fbDaI7XbGbXNmn4JAdEGYGhQ3gEb 0ICTUgyObNsDnXt2dzQoRIItFNomoal5O8FiPAhqrhYo+N0tx742UBovSFy1l/a1 2Lh26IfupSXl668YBpiWELqZeYQkcX5NnGkMcrJoLSq51FZYcCsLUMPKLVccWfE3 uWMTNG+o7BYgzjFs9SwzeptL+BbCa6dlKLSZ75UeabMWrtuTRMUvIMMdv/rNJGpJ J4WrfTFUv5aR/i9dMKQM =CC0f -----END PGP SIGNATURE----- From owner-dnssec-trac at kirei.se Fri May 6 12:14:24 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 12:14:24 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #238: Resalt lower then Resign: ods-kaspcheck validates Message-ID: <057.921d2882a96b316a9e488a0249716993@kirei.se> #238: Resalt lower then Resign: ods-kaspcheck validates --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: 1.2.1 | Keywords: --------------------------------+------------------------------------------- Teststeps: - Set the Resalt time lower than the resign - Update configuration - Check if ods-kaspcheck fails Expected result: - ods-kaspcheck fails for kasp.xml Observed result: - ods-kaspcheck validates (used config files have been attached.) -- Ticket URL: OpenDNSSEC OpenDNSSEC From olaf at NLnetLabs.nl Fri May 6 12:16:22 2011 From: olaf at NLnetLabs.nl (Olaf Kolkman) Date: Fri, 6 May 2011 14:16:22 +0200 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #231: Configure fails on mysql_version substitution In-Reply-To: <070.5684a21f6ed1e76c393f8989b0b73fda@kirei.se> References: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> <070.5684a21f6ed1e76c393f8989b0b73fda@kirei.se> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yes it seems so On May 6, 2011, at 9:05 AM, OpenDNSSEC wrote: > #231: Configure fails on mysql_version substitution > ------------------------------+--------------------------------------------- > Reporter: Olaf@? | Owner: rb > Type: defect | Status: new > Priority: major | Component: Unknown > Version: trunk | Resolution: > Keywords: configure | > ------------------------------+--------------------------------------------- > > Comment (by rb): > > Perhaps this is better? > > {{{ > Index: OpenDNSSEC/m4/acx_mysql.m4 > =================================================================== > --- OpenDNSSEC/m4/acx_mysql.m4 (revision 5033) > +++ OpenDNSSEC/m4/acx_mysql.m4 (working copy) > @@ -17,8 +17,9 @@ > if test -x "$MYSQL_CONFIG"; then > AC_MSG_CHECKING(mysql version) > MYSQL_VERSION="`$MYSQL_CONFIG --version`" > + MYSQL_VERSION_MAJOR=`echo "$MYSQL_VERSION" | sed -e > 's/\..*//'` > AC_MSG_RESULT($MYSQL_VERSION) > - if test ${MYSQL_VERSION//.*/} -le 4 ; then > + if test ${MYSQL_VERSION_MAJOR} -le 4 ; then > AC_MSG_ERROR([mysql must be newer than 5.0.0]) > fi > }}} > > -- > Ticket URL: > OpenDNSSEC > OpenDNSSEC ________________________________________________________ Olaf M. Kolkman NLnet Labs http://www.nlnetlabs.nl/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: This message is locally signed. Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJNw+aWAAoJEFRqER47aqpkc34P/jj3V68Ym4QXJgIMHXJaf2XO YSBhNCOM9Y9Mouv/PTsD/3yDxg1JZm5Oqb7K6WMvrIL47TPevGoZ70M5b+FDmlz4 eIhGZQdUd5zyDsL5Ayo3UdxjWc+/fxs5u5RSSuEalx2ug7uvy9qFtOrt43Wox2KF FwnEQosQPzKyppbh1AmsuhcbtqEDXcW4m45ynWiJZN6wMxhqTv5U3+vamI8VFgCf iLlCbIB5GV5j3zYUw1fk9YR58bTO7e8PRHFlyt8mw8aRPLVSu5HFHTyUGLw0mv3q ZBnmRtSz86HvY6PPT/xSRtTTLnQtNtI0QDp9upJo1l6V8eu+CJX8Qw4mDLHnVbKh x1FRYTilSvcfX8lNcIcBjhwTUyqDNfSyRCaGGQb2MC4RNrCkAImpV0UP5gmF7h8c PczGLSeF5bELC9MqcMhKGVPa8FHN/4VxN5yEq8CoLvjqdsy21ItLSs4oMUGgL91y 5TaR8sC/uSZ7WyPTsypcEDSqykx5842oD2grexG9R8y9w8cyOVD8xS6wM+VXUSky 79JT/3ibaK1Fr0A5B0ObF42Zmkvd4BlTF13yGL+o+PwTwbNte1uzuJHdDdl6yKPy Ra5lZr/hE7SWM8aEMohQYgJnJITu9jZ9VrONWRPgWJNiybQeMkuHLfOHaYV0kizg WGLa3jFJrIT9JMOzZIZx =mWIh -----END PGP SIGNATURE----- From owner-dnssec-trac at kirei.se Fri May 6 13:40:56 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 06 May 2011 13:40:56 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #231: Configure fails on mysql_version substitution In-Reply-To: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> References: <055.1a94f949e2e00f6bf209ece964764585@kirei.se> Message-ID: <070.f5ee82fc4365f5b200be19324bfcf79b@kirei.se> #231: Configure fails on mysql_version substitution ------------------------------+--------------------------------------------- Reporter: Olaf@? | Owner: rb Type: defect | Status: closed Priority: major | Component: Unknown Version: trunk | Resolution: fixed Keywords: configure | ------------------------------+--------------------------------------------- Changes (by rb): * status: new => closed * resolution: => fixed Comment: Thanks, fixed in r5071 -- Ticket URL: OpenDNSSEC OpenDNSSEC From rickard at opendnssec.org Mon May 9 08:29:08 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 9 May 2011 10:29:08 +0200 Subject: [Opendnssec-develop] Meeting 20110512 Message-ID: Hi It is time for a meeting on Thursday. I cannot attend the meeting, so would anyone like to chair it? Date: Thursday 12 May Time: 14:00-15:00 CEST, 13:00-14:00 BST http://trac.opendnssec.org/wiki/Meetings/Agenda/2011-05-12 // Rickard From rickard at opendnssec.org Mon May 9 08:44:51 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 9 May 2011 10:44:51 +0200 Subject: [Opendnssec-develop] Fwd: SoftHSM 1.2.1 In-Reply-To: <201105072210.p47M9xq7024042@bartok.nlnetlabs.nl> References: <201105072210.p47M9xq7024042@bartok.nlnetlabs.nl> Message-ID: Hi This also applies to all of our dependency checks. Should we change the default path (/usr/local) to $prefix in all of our .m4 files? // Rickard ---------- Forwarded message ---------- From: Jaap Akkerhuis Date: Sun, May 8, 2011 at 12:09 AM Subject: Re: [Opendnssec-announce] SoftHSM 1.2.1 To: Rickard Bellgrim Cc: Matthijs Mekking ? ?Version 1.2.1 of SoftHSM has now been released. This version hit the ports of FreeBSD. However it was pointed out to me that that there is actually a problem in the configure process. (Apparently it is an old one but has been noticed/reported before). It boils down to the fact that the path to botan is hard-wired in. If one does --prefix/foo, that is not always followed and one is required to set --with-botan=/foo as well. This can be fixed changing by changing in configure ? ? ? ?BOTAN_PATH="/usr/local" into ? ? ? ?BOTAN_PATH="$prefix" A similar change should be made for sqlite3 as well. Regards, ? ? ? ?jaap From jakob at kirei.se Wed May 11 03:17:17 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Wed, 11 May 2011 05:17:17 +0200 Subject: [Opendnssec-develop] Meeting 20110512 In-Reply-To: References: Message-ID: On 9 maj 2011, at 10.29, Rickard Bellgrim wrote: > It is time for a meeting on Thursday. I cannot attend the meeting, so > would anyone like to chair it? I'll take care of it. jakob From rickard at opendnssec.org Wed May 11 06:13:47 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Wed, 11 May 2011 08:13:47 +0200 Subject: [Opendnssec-develop] Meeting 20110512 In-Reply-To: References: Message-ID: Thanks again Jakob! On Wed, May 11, 2011 at 5:17 AM, Jakob Schlyter wrote: > On 9 maj 2011, at 10.29, Rickard Bellgrim wrote: > >> It is time for a meeting on Thursday. I cannot attend the meeting, so >> would anyone like to chair it? > > I'll take care of it. > > ? ? ? ?jakob > > From owner-dnssec-trac at kirei.se Thu May 12 12:07:13 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 12 May 2011 12:07:13 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #238: Resalt lower then Resign: ods-kaspcheck validates In-Reply-To: <057.921d2882a96b316a9e488a0249716993@kirei.se> References: <057.921d2882a96b316a9e488a0249716993@kirei.se> Message-ID: <072.14a1e9e03ac8197de0ccc8d0686b0cee@kirei.se> #238: Resalt lower then Resign: ods-kaspcheck validates --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: alex Type: defect | Status: assigned Priority: major | Component: Unknown Version: 1.2.1 | Resolution: Keywords: | --------------------------------+------------------------------------------- Changes (by jakob): * owner: rb => alex * status: new => assigned -- Ticket URL: OpenDNSSEC OpenDNSSEC From matthijs at NLnetLabs.nl Thu May 12 12:50:21 2011 From: matthijs at NLnetLabs.nl (Matthijs Mekking) Date: Thu, 12 May 2011 14:50:21 +0200 Subject: [Opendnssec-develop] Meeting Minutes Thu May 12 Message-ID: <4DCBD78D.4030301@nlnetlabs.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 http://trac.opendnssec.org/wiki/Meetings/Minutes/2011-05-12 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJNy9eNAAoJEA8yVCPsQCW5KfAH/2VFTgG5BdykG7vDkCEJfvH2 5pm3jV7jG6mL/YOlpg7sOuCXRW0Op8Pq3SE/41lu2O/afxKn5tQn+0QnoWdreuL1 MFfGqnhmusyRDzCoYIfdH40sdoi3HFAUwfig9Xr+XCabaWWvYTeIwjKhgaeBC6E8 0HosdQ4YeGu26ivvd6d3iFyaPqmQgSN8ORw9HTyEwpo4eG31YUPJ4C80+906dAfr ofCTeytmwGPKxBr+FuD2pnE6SVrTTwbuECNAuYyq2QS56WZlWabufnlZ3sJ2pv8C uFPYue/Z29y4h1nbeVkCrtayZ0QlNKxUIrJNsLSqBtxNoJ9snfbjYWhIWyeoaTU= =9Dng -----END PGP SIGNATURE----- From nick.vandenheuvel at sidn.nl Thu May 12 13:03:36 2011 From: nick.vandenheuvel at sidn.nl (Nick van den Heuvel) Date: Thu, 12 May 2011 13:03:36 +0000 Subject: [Opendnssec-develop] Meeting Minutes Thu May 12 In-Reply-To: <4DCBD78D.4030301@nlnetlabs.nl> References: <4DCBD78D.4030301@nlnetlabs.nl> Message-ID: Hallo Matthijs, Hierbij de testresultaten van 1.2.1. Voor 1.3.0rc1 zullen ze in het engels komen. Ik had verzuimd om ze met jou te delen. Antoin had deze rapportages vorige week al gekregen en ik had hem een update gestuurd van de huidige stand van zaken. Ik zal a.s. maandag weer een update naar de repository sturen. Gr. Nick Nick van den Heuvel Testanalist SIDN | Utrechtseweg 310 | 6812 AR | Postbus 5022 | 6802 EA | ARNHEM T +31 (0)26 352 55 00 | F +31 (0)26 352 55 05 nick.vandenheuvel at sidn.nl | www.sidn.nl -----Original Message----- From: opendnssec-develop-bounces at lists.opendnssec.org [mailto:opendnssec-develop-bounces at lists.opendnssec.org] On Behalf Of Matthijs Mekking Sent: donderdag 12 mei 2011 14:50 To: opendnssec-develop at lists.opendnssec.org Subject: [Opendnssec-develop] Meeting Minutes Thu May 12 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 http://trac.opendnssec.org/wiki/Meetings/Minutes/2011-05-12 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJNy9eNAAoJEA8yVCPsQCW5KfAH/2VFTgG5BdykG7vDkCEJfvH2 5pm3jV7jG6mL/YOlpg7sOuCXRW0Op8Pq3SE/41lu2O/afxKn5tQn+0QnoWdreuL1 MFfGqnhmusyRDzCoYIfdH40sdoi3HFAUwfig9Xr+XCabaWWvYTeIwjKhgaeBC6E8 0HosdQ4YeGu26ivvd6d3iFyaPqmQgSN8ORw9HTyEwpo4eG31YUPJ4C80+906dAfr ofCTeytmwGPKxBr+FuD2pnE6SVrTTwbuECNAuYyq2QS56WZlWabufnlZ3sJ2pv8C uFPYue/Z29y4h1nbeVkCrtayZ0QlNKxUIrJNsLSqBtxNoJ9snfbjYWhIWyeoaTU= =9Dng -----END PGP SIGNATURE----- _______________________________________________ Opendnssec-develop mailing list Opendnssec-develop at lists.opendnssec.org https://lists.opendnssec.org/mailman/listinfo/opendnssec-develop -------------- next part -------------- A non-text attachment was scrubbed... Name: Samenvatting resultaat OpenDNSSEC 1.2.1_run6.doc Type: application/msword Size: 214528 bytes Desc: Samenvatting resultaat OpenDNSSEC 1.2.1_run6.doc URL: From owner-dnssec-trac at kirei.se Thu May 12 13:04:44 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 12 May 2011 13:04:44 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #238: Resalt lower then Resign: ods-kaspcheck validates In-Reply-To: <057.921d2882a96b316a9e488a0249716993@kirei.se> References: <057.921d2882a96b316a9e488a0249716993@kirei.se> Message-ID: <072.878ee421ed4e6299a36d21a1ab6b4954@kirei.se> #238: Resalt lower then Resign: ods-kaspcheck validates --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: alex Type: defect | Status: assigned Priority: major | Component: Unknown Version: 1.2.1 | Resolution: Keywords: | --------------------------------+------------------------------------------- Comment (by alex): Fixed for 1.3.0 in svn r5094 -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Thu May 12 13:04:53 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 12 May 2011 13:04:53 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #238: Resalt lower then Resign: ods-kaspcheck validates In-Reply-To: <057.921d2882a96b316a9e488a0249716993@kirei.se> References: <057.921d2882a96b316a9e488a0249716993@kirei.se> Message-ID: <072.22fb4b53107daf6f71772fa428d715f7@kirei.se> #238: Resalt lower then Resign: ods-kaspcheck validates --------------------------------+------------------------------------------- Reporter: Nick van den Heuvel | Owner: alex Type: defect | Status: closed Priority: major | Component: Unknown Version: 1.2.1 | Resolution: fixed Keywords: | --------------------------------+------------------------------------------- Changes (by alex): * status: assigned => closed * resolution: => fixed -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Mon May 16 09:32:54 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Mon, 16 May 2011 09:32:54 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #232: apostrophe in description and mysql In-Reply-To: <055.a5fa26cb9a6ddebfb58bc49b96c2380b@kirei.se> References: <055.a5fa26cb9a6ddebfb58bc49b96c2380b@kirei.se> Message-ID: <070.017d0c3eb6e95d76bc0d327ff0a7053f@kirei.se> #232: apostrophe in description and mysql ------------------------------+--------------------------------------------- Reporter: olaf@? | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Resolution: Keywords: configure mysql | ------------------------------+--------------------------------------------- Comment (by rb): This will be marked as a known issue in v1.3.0. -- Ticket URL: OpenDNSSEC OpenDNSSEC From sion at nominet.org.uk Mon May 16 14:50:32 2011 From: sion at nominet.org.uk (=?ISO-8859-1?Q?Si=F4n_Lloyd?=) Date: Mon, 16 May 2011 15:50:32 +0100 Subject: [Opendnssec-develop] signconf.rnc Message-ID: <4DD139B8.5000002@nominet.org.uk> Does anyone object to me changing the "element Iterations" entry in the NSEC3 blob to be a nonNegativeInteger instead of a positiveInteger? This will allow an iterations value of 0... (I'm guessing that the python signer never checked the signconfs?) Then, more importantly, do we need to patch this fix back into the 1.2 branch? Cheers, Sion From jakob at kirei.se Mon May 16 19:07:29 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Mon, 16 May 2011 21:07:29 +0200 Subject: [Opendnssec-develop] signconf.rnc In-Reply-To: <4DD139B8.5000002@nominet.org.uk> References: <4DD139B8.5000002@nominet.org.uk> Message-ID: <58232EA4-F519-4F93-A8E6-963BD2806600@kirei.se> On 16 maj 2011, at 16.50, Si?n Lloyd wrote: > Does anyone object to me changing the "element Iterations" entry in the NSEC3 blob to be a nonNegativeInteger instead of a positiveInteger? Is zero iterations correctly implemented in the signer engine? jakob From sion at nominet.org.uk Tue May 17 08:19:41 2011 From: sion at nominet.org.uk (=?ISO-8859-1?Q?Si=F4n_Lloyd?=) Date: Tue, 17 May 2011 09:19:41 +0100 Subject: [Opendnssec-develop] signconf.rnc In-Reply-To: <58232EA4-F519-4F93-A8E6-963BD2806600@kirei.se> References: <4DD139B8.5000002@nominet.org.uk> <58232EA4-F519-4F93-A8E6-963BD2806600@kirei.se> Message-ID: <4DD22F9D.6070000@nominet.org.uk> On 16/05/11 20:07, Jakob Schlyter wrote: > On 16 maj 2011, at 16.50, Si?n Lloyd wrote: > >> Does anyone object to me changing the "element Iterations" entry in the NSEC3 blob to be a nonNegativeInteger instead of a positiveInteger? > Is zero iterations correctly implemented in the signer engine? > It works for v1.2.1 and trunk (at least my zone signs and audits). Sion From matthijs at NLnetLabs.nl Tue May 17 08:23:48 2011 From: matthijs at NLnetLabs.nl (Matthijs Mekking) Date: Tue, 17 May 2011 10:23:48 +0200 Subject: [Opendnssec-develop] signconf.rnc In-Reply-To: <4DD139B8.5000002@nominet.org.uk> References: <4DD139B8.5000002@nominet.org.uk> Message-ID: <4DD23094.6020605@nlnetlabs.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Fine with me. The python code never did a RNG check. The c code currently does not either (as I encountered segfault in the code). Best regards, Matthijs On 05/16/2011 04:50 PM, Si?n Lloyd wrote: > Does anyone object to me changing the "element Iterations" entry in the > NSEC3 blob to be a nonNegativeInteger instead of a positiveInteger? > > This will allow an iterations value of 0... (I'm guessing that the > python signer never checked the signconfs?) > > Then, more importantly, do we need to patch this fix back into the 1.2 > branch? > > Cheers, > > Sion > _______________________________________________ > Opendnssec-develop mailing list > Opendnssec-develop at lists.opendnssec.org > https://lists.opendnssec.org/mailman/listinfo/opendnssec-develop -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJN0jCUAAoJEA8yVCPsQCW5WFAIAJUm288u8Ctytu4ZXQ/6sQ3N LRL+CnA4ws39xptA8IfydTdTufA0ltVJDym6RuELn8EomBtT63M3GtkJp0kWIQ7I L0gYlftahOSMx5xK0A1qSF5lIs1FdEpbWfrOFxD3HJCeyHHxjDO4kpgfIkPDg4WX ZAvmyyooyzA2dDWQoRH9UAZzxRTYPMXZuWKxJWZjkAdPOYNyodsd91t21YfBdbkY CilCLzsPP0/Pj5wtE0t+A/Au8mYQ5qoFF35kNKxqOZcuQZvVG4HbvoA8vc9rB4dF gm3bdKbeghQ0DREL+exNcd0nw8BeiE5rNswXIgsxqKchTIC+LTJ3GuP5BPzGY1k= =RzsF -----END PGP SIGNATURE----- From jakob at kirei.se Tue May 17 10:25:33 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Tue, 17 May 2011 12:25:33 +0200 Subject: [Opendnssec-develop] signconf.rnc In-Reply-To: <4DD22F9D.6070000@nominet.org.uk> References: <4DD139B8.5000002@nominet.org.uk> <58232EA4-F519-4F93-A8E6-963BD2806600@kirei.se> <4DD22F9D.6070000@nominet.org.uk> Message-ID: <8DC59367-AA75-4452-B36D-C3DE75685ED3@kirei.se> On 17 maj 2011, at 10.19, Si?n Lloyd wrote: > It works for v1.2.1 and trunk (at least my zone signs and audits). In that case, please go ahead. Please also update the 1.3 branch and the NEWS file. jakob From rickard at opendnssec.org Wed May 18 08:07:22 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Wed, 18 May 2011 10:07:22 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files Message-ID: Hi I am struggling with OpenDNSSEC on Ubuntu 10.04. I cannot find a compatible version of the jar command which builds the .rng files. On Ubuntu 8.04 there was a jar command from Sun, but is gone on the 10.04. There are other jar commands but they do not have the same command line options. Am I doing something wrong? // Rickard From jakob at kirei.se Wed May 18 08:21:40 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Wed, 18 May 2011 10:21:40 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: References: Message-ID: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> On 18 maj 2011, at 10.07, Rickard Bellgrim wrote: > I am struggling with OpenDNSSEC on Ubuntu 10.04. I cannot find a > compatible version of the jar command which builds the .rng files. On > Ubuntu 8.04 there was a jar command from Sun, but is gone on the > 10.04. There are other jar commands but they do not have the same > command line options. jar? are you perhaps referring to trang [1]? jakob [1] http://jing-trang.googlecode.com/files/trang-20081028.zip -- Jakob Schlyter Kirei AB - http://www.kirei.se/ From rickard at opendnssec.org Wed May 18 09:25:10 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Wed, 18 May 2011 11:25:10 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> References: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> Message-ID: I get this: rickardb at zonehsm:~/ods-svn/branches/OpenDNSSEC-1.3/build/conf$ make jar ../../conf/trang/trang.jar ../../conf/conf.rnc conf.rng /bin/bash: jar: command not found make: [conf.rng] Error 127 (ignored) jar ../../conf/trang/trang.jar ../../conf/kasp.rnc kasp.rng /bin/bash: jar: command not found make: [kasp.rng] Error 127 (ignored) jar ../../conf/trang/trang.jar ../../conf/zonelist.rnc zonelist.rng /bin/bash: jar: command not found make: [zonelist.rng] Error 127 (ignored) jar ../../conf/trang/trang.jar ../../conf/signconf.rnc signconf.rng /bin/bash: jar: command not found make: [signconf.rng] Error 127 (ignored) jar ../../conf/trang/trang.jar ../../conf/zonefetch.rnc zonefetch.rng /bin/bash: jar: command not found make: [zonefetch.rng] Error 127 (ignored) On Wed, May 18, 2011 at 10:21 AM, Jakob Schlyter wrote: > On 18 maj 2011, at 10.07, Rickard Bellgrim wrote: > >> I am struggling with OpenDNSSEC on Ubuntu 10.04. I cannot find a >> compatible version of the jar command which builds the .rng files. On >> Ubuntu 8.04 there was a jar command from Sun, but is gone on the >> 10.04. There are other jar commands but they do not have the same >> command line options. > > jar? are you perhaps referring to trang [1]? > > ? ? ? ?jakob > > > [1] http://jing-trang.googlecode.com/files/trang-20081028.zip > > -- > Jakob Schlyter > Kirei AB - http://www.kirei.se/ > > From jakob at kirei.se Wed May 18 09:29:59 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Wed, 18 May 2011 11:29:59 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: References: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> Message-ID: On 18 maj 2011, at 11.25, Rickard Bellgrim wrote: > rickardb at zonehsm:~/ods-svn/branches/OpenDNSSEC-1.3/build/conf$ make > jar ../../conf/trang/trang.jar ../../conf/conf.rnc conf.rng > /bin/bash: jar: command not found You are missing a Java Runtime Environment (JRE), not JAR. Did configure fine one? jakob From rickard at opendnssec.org Wed May 18 11:11:55 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Wed, 18 May 2011 13:11:55 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: References: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> Message-ID: Yes, the JRE was missing. However, conf/Makefile.am did not catch this. The ${JAVA} was empty. On Wed, May 18, 2011 at 11:29 AM, Jakob Schlyter wrote: > On 18 maj 2011, at 11.25, Rickard Bellgrim wrote: > >> rickardb at zonehsm:~/ods-svn/branches/OpenDNSSEC-1.3/build/conf$ make >> jar ../../conf/trang/trang.jar ../../conf/conf.rnc conf.rng >> /bin/bash: jar: command not found > > You are missing a Java Runtime Environment (JRE), not JAR. Did configure fine one? > > ? ? ? ?jakob > > From owner-dnssec-trac at kirei.se Wed May 18 11:28:42 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 11:28:42 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #239: Stop distributing trang.jar Message-ID: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> #239: Stop distributing trang.jar ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Keywords: ------------------------------------------+--------------------------------- Per http://trac.opendnssec.org/ticket/77#comment:3 I remember that I saw a patch from Jakob floating somewhere which removed trang (which is needed only when you make tarball), but it never was included. It would simplify my work if I don't have to repack tarball everytime I create opendnssec packages. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 11:32:53 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 11:32:53 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #240: Remove $Id tags from configuration files Message-ID: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Keywords: ------------------------------------------+--------------------------------- Hi, this is more wishlist-like bug. It would make things simpler if the installed .xml files didn't have $Id tags. The problem is that $Id tag creates changes in the conffile even when there are no real changes. Example diff from 1.2.1 -> 1.3.0rc2 {{{ diff --git a/conf/kasp.xml.in b/conf/kasp.xml.in index 674cc39..68a4325 100644 --- a/conf/kasp.xml.in +++ b/conf/kasp.xml.in @@ -1,6 +1,6 @@ - + + + }}} Again this is something I can handle in the package scripts, but it would be nice to have (and all users would benefit from this). O. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 11:46:47 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 11:46:47 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #239: Stop distributing trang.jar In-Reply-To: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> References: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> Message-ID: <080.b2d666c4cd56459bfcbe3b2d4e2cc93f@kirei.se> #239: Stop distributing trang.jar ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: jakob Type: enhancement | Status: assigned Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Changes (by jakob): * owner: rb => jakob * status: new => assigned -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 11:52:08 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 11:52:08 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #239: Stop distributing trang.jar In-Reply-To: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> References: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> Message-ID: <080.ad94b74ebb75d725e8913e97352843cf@kirei.se> #239: Stop distributing trang.jar ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: jakob Type: enhancement | Status: assigned Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by jakob): Fix included in trunk, r5139, please test. -- Ticket URL: OpenDNSSEC OpenDNSSEC From jakob at kirei.se Wed May 18 12:01:25 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Wed, 18 May 2011 14:01:25 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: References: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> Message-ID: <47C07669-729A-493A-9227-20CF8B2A141B@kirei.se> On 18 maj 2011, at 13.11, Rickard Bellgrim wrote: > Yes, the JRE was missing. However, conf/Makefile.am did not catch > this. The ${JAVA} was empty. Thanks - I just fixed this in rev 5140, please test. jakob From owner-dnssec-trac at kirei.se Wed May 18 12:18:21 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 12:18:21 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #239: Stop distributing trang.jar In-Reply-To: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> References: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> Message-ID: <080.6cbf859738791ba97ff8333c8798ebe1@kirei.se> #239: Stop distributing trang.jar ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: jakob Type: enhancement | Status: assigned Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by Ond?ej Sur? ): Tested and confirming as fixed. The generated tarball (after doing make dist) doesn't have trang directory anymore. Thank you very much. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 12:18:40 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 12:18:40 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #241: make dist in trunk fails Message-ID: <065.3ccbc0219f38890e28afbd0cb0ebf517@kirei.se> #241: make dist in trunk fails ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ------------------------------------------+--------------------------------- make[1]: Leaving directory `/root/OpenDNSSEC/auditor' (cd plugins/eppclient && make top_distdir=../../opendnssec-1.4.0-trunk distdir=../../opendnssec-1.4.0-trunk/plugins/eppclient \ am__remove_distdir=: am__skip_length_check=: am__skip_mode_fix=: distdir) make[1]: Entering directory `/root/OpenDNSSEC/plugins/eppclient' make[1]: *** No rule to make target `distdir'. Stop. make[1]: Leaving directory `/root/OpenDNSSEC/plugins/eppclient' make: *** [distdir] Error 1 Removing plugin/eppclient from DIST_SUBDIRs list in the generated Makefile helps. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 12:19:43 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 12:19:43 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #241: make dist in trunk fails In-Reply-To: <065.3ccbc0219f38890e28afbd0cb0ebf517@kirei.se> References: <065.3ccbc0219f38890e28afbd0cb0ebf517@kirei.se> Message-ID: <080.ce8fb83ffc6e4eed0a10858077fb0216@kirei.se> #241: make dist in trunk fails ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by Ond?ej Sur? ): Reformat: {{{ make[1]: Leaving directory `/root/OpenDNSSEC/auditor' (cd plugins/eppclient && make top_distdir=../../opendnssec-1.4.0-trunk distdir=../../opendnssec-1.4.0-trunk/plugins/eppclient \ am__remove_distdir=: am__skip_length_check=: am__skip_mode_fix=: distdir) make[1]: Entering directory `/root/OpenDNSSEC/plugins/eppclient' make[1]: *** No rule to make target `distdir'. Stop. make[1]: Leaving directory `/root/OpenDNSSEC/plugins/eppclient' make: *** [distdir] Error 1 }}} And small clarification - the --disable/enable-eppclient doesn't affect this bug. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Wed May 18 12:20:42 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Wed, 18 May 2011 12:20:42 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #239: Stop distributing trang.jar In-Reply-To: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> References: <065.02c38b317be5d7d6ace6903f0ab9852e@kirei.se> Message-ID: <080.cbe8509a89fea02a29c644b0cdbe4b66@kirei.se> #239: Stop distributing trang.jar ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: jakob Type: enhancement | Status: closed Priority: trivial | Component: Unknown Version: trunk | Resolution: fixed Keywords: | ------------------------------------------+--------------------------------- Changes (by jakob): * status: assigned => closed * resolution: => fixed -- Ticket URL: OpenDNSSEC OpenDNSSEC From rickard at opendnssec.org Wed May 18 13:33:04 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Wed, 18 May 2011 15:33:04 +0200 Subject: [Opendnssec-develop] The jar command for the .rng files In-Reply-To: <47C07669-729A-493A-9227-20CF8B2A141B@kirei.se> References: <33585B06-5988-4629-A5C3-70637E825675@kirei.se> <47C07669-729A-493A-9227-20CF8B2A141B@kirei.se> Message-ID: Thanks, it works. On Wed, May 18, 2011 at 2:01 PM, Jakob Schlyter wrote: > On 18 maj 2011, at 13.11, Rickard Bellgrim wrote: > >> Yes, the JRE was missing. However, conf/Makefile.am did not catch >> this. The ${JAVA} was empty. > > Thanks - I just fixed this in rev 5140, please test. > > ? ? ? ?jakob > > From owner-dnssec-trac at kirei.se Thu May 19 03:47:08 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Thu, 19 May 2011 03:47:08 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #242: Race condition when receiving multiple NOTIFIES for a zone Message-ID: <078.a9b4bb255040558f07a1d4ffcd8a4f92@kirei.se> #242: Race condition when receiving multiple NOTIFIES for a zone -----------------------------------------------------+---------------------- Reporter: Sebastian Castro | Owner: matthijs Type: defect | Status: new Priority: major | Component: Signer Version: 1.2.1 | Keywords: -----------------------------------------------------+---------------------- We observed a weird behavior in our test system: truncated .axfr files. In our setup, a signer can receive a zone from two different sources. Each of this "sources" generates a new zone every hour, so it's perfectly possible for them to send a NOTIFY message to the signer at the same time for the same zone. In 1.2.1, there is no logic to prevent concurrent zone transfers for the same zone at the same time, which means they will write to the same file at some point. We prepared a code to send simultaneous NOTIFY to a signer, and we ended with messages like this: May 19 15:13:51 srsov ods-signerd: zone fetcher received NOTIFY for zone school.nz May 19 15:13:52 srsov ods-signerd: zone fetcher transferred zone school.nz serial 2011051921 successfully May 19 15:13:52 srsov ods-signerd: cmdhandler: zone school.nz scheduled for immediate re-sign May 19 15:13:52 srsov ods-signerd: zone fetcher received NOTIFY for zone school.nz May 19 15:13:52 srsov ods-signerd: zone fetcher transferred zone school.nz serial 2011051921 successfully May 19 15:13:52 srsov ods-signerd: cmdhandler: already performing task for zone school.nz In this case, the signing tasklist detects something was going on, but we have seen other cases where the input zone ends mangled. This adversely affects our ability to handle disastrous scenarios. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 01:42:41 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 01:42:41 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #243: Features of DeMarini CF3 Bat through DeMarini Bats Message-ID: <047.b7e339187f84b3f82b4a81ad1cdb4319@kirei.se> #243: Features of DeMarini CF3 Bat through DeMarini Bats ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Features of DeMarini CF3 Bat through DeMarini Bats [http://www.baseballbathq.com DeMarini Bats] very first burst within 1989 as well as guaranteed its appreciated gamers for that production of high tech bats. The production of DeMarini Bats turned out to be the breakthrough in the football as well as competitive softball industry. It has created amounts of bats which ranges through amalgamated, hybrid as well as metal options and also have taken part in the numbers of University titles. Using the best selection of bats Vexxum, Vendatta, [http://www.baseballbathq.com/demarini-voodoo DeMarini Voodoo] as well as [http://www.baseballbathq.com/demarini-cf3/ DeMarini CF3 Bat], the company has become the leading company in the market. Sturdiness as well as high level overall performance is associated with all the DeMarini Bats. Let???s possess brief review of DeMarini CF3 Bat functions. DeMarini CF3 Bat is made of the more powerful co2 material which guarantees to provide the larger sweet place as well as add energy and accuracy to the softball video games. Some leading functions are: Technologies: DeMarini CF3 Bat makes use of the message black amalgamated technology as well as guarantees our prime level overall performance in most online game. It makes the dynamic hitting surface as well as optimum trampoline effect. Additionally, it ensures the maximum optimum flex and with the use of effective double walls technologies it ensures the actual strongest and the smallest compositing outcomes. Material: DeMarini CF3 Bat makes use of mixture of compositing materials to create the actual bats most powerful and durable. Using carbon materials entails the most sweet spots and higher hitting pace. It's created using the actual slim walls pitch dark materials to include strength to the gun barrel. Weight and size: DeMarini CF3 Bat is actually Five weight to duration percentage that makes it ideal for any type of strike. The barrel is actually associated with 5/8??? and the length of DeMarini CF3 Bat is actually 32??? and 33???. The various lengths as well as weights ensure various amounts and striking designs. Grip: Using message dark manage maximizes the bend and also the power associated with DeMarini CF3 Bat. It also grants or loans the restricted and comfy hold by reduction of the oscillations. Accomplishments: DeMarini CF3 Bat has fulfilled the performance standards of Usa niche sports association, Amateur competitive softball association, Nationwide softball organization and also the independent softball association. These types of businesses assess the bat upon dimension, overall performance and fat. The Precious metal edition associated with DeMarini CF3 Bat offers accomplished the actual Gold honor from USA. All these options that come with DeMarini CF3 Bat and the accomplishments produced by this bat surely allow it to be the best option within the softball business. So what have you been awaiting? Go as well as get your own DeMarini CF3 Bat. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 02:20:47 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 02:20:47 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #244: Promotional Vehicles as well as Roadshow Trailers to provide a brand new Area of Presence Message-ID: <047.0d3b718fb67ca500e1df25adf2cd3acb@kirei.se> #244: Promotional Vehicles as well as Roadshow Trailers to provide a brand new Area of Presence ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Promotional Vehicles as well as Roadshow Trailers to provide a brand new Area of Presence The actual trailers that are used for mobile exhibitions for different factors are now the brand new way to achieve towards the bulk with a brand new idea or perhaps a cool product that has some promises for them. The common people come to are conscious of the actual [http://www.eventms.com Exhibition trailers] when they are produced in front of these to provide shape to a new product on the market. The actual static displays of new items within the conventional displays have grown to be slow to reach to the mass and then the new position would be to achieve to folks with the cellular exhibitions to enable them to consider all of them with out throwing away enough time as well as form their own viewpoint. The new event administration organizations feel that the actual novel method to reach people with an easy idea of a brand new wellness consume or even an taken care of promotion for a new album of the vocalist can be brought within the area associated with common people through the help of the actual [http://www.eventms.com/content/Sectors/Socialmarketing/SMVehicles.aspx Promotional Vehicles]. They can mount the current suggestions that may get to the common individuals. The most popular individuals then consider a good constant curiosity about the item or the recording or the exhibition and regales within the benefits of experiencing the item. The actual promotion thus works well for marketing as well as mentioning a new product or sometime provides port with a sociable communications and an unique side of the social mismanagement. The big or even small trailers which are used for these reasons tend to be coming up in various sizes and taking up various duties by completely monopolizing the mass interest in an applications of the [http://www.eventms.com/content/landingpages/roadshowtrailers.aspx Roadshow Trailers]. The roadshows can be a part of a politics marketing or an advertising campaign or perhaps an easy way to say that a particular new concept or perhaps a method is far better for you now therefore - the common people takes up the new ideas from them as well as attempts them in life. The actual trailers can be of various shapes and sizes according to the marketing campaign that it takes part in. They're decorated in a different way in different marketing and therefore are versatile in ways so that different business may remodel the d??cor with their personal brand name and color mixture that meets them. The makers make them strong and hardy and they are available in different prize variety for varied degree of requisition. The trailers are pulled with a vehicle which has the ability to draw it also it moves around within the surrounding area to reach the people with their own selection of shows. The businesses now have a different way to keep the general individuals aware of different state associated with artwork items and concepts and ideas so the presence is never lost. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 03:08:18 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 03:08:18 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #245: Check Out The Car Insurance Quotes Online Message-ID: <047.673bf93352eebe226463469721e2e3df@kirei.se> #245: Check Out The Car Insurance Quotes Online ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Check Out The Car Insurance Quotes Online Are you planning to obtain the [http://www.insurancequotes.org.za car insurance quotes] on the internet? This is certainly a sensible concept because searching for the quotes on the internet, and finalizing the offer can certainly help you save time. Using the advent of the web, many of the situations are completed on the internet. Consequently, getting the quotes and covering the actual car with the internet is not at all challenging. There are lots of companies that offer their own providers on the internet. If you check out the internet, you would find innumerable insurance companies with their web host of policies, quotes and premiums. You can easily have a look at these types of policies provided by the various companies before you reach your final decision. However, because there are countless options, you might often face trouble for making the right choice. Consequently, the foremost and the foremost factor that you must do are to browse the genuineness from the web site. This is important if the site is not authentic, you wouldn't be capable of geting reliable [http://www.insurancequotes.org.za insurance quotes]. Simultaneously, you might also create a wrong choice concerning the selection of the company and the plan. Consequently, be cautious, and then try to complete your deal with a reliable company. A good thing that you can do in this instance would be to browse the evaluations from the various websites. Within the evaluations, you wouldn't just obtain concept about the different businesses, however at the same time, you would will also get idea on the guidelines and the [http://www.insurancequotes.org.za car insurance quote]. Therefore, even if, you are not assured concerning the choice of a policy, you'll have a consider the different evaluations and make a decision after acquiring idea from this. The reviews that you would obtain from the reliable sites are usually reliable, and therefore, you would not have to be worried about it. There are millions of people that are choosing the quote as well as finalizing their offer on the internet. Consequently, you would not have to be worried when you are planning to manage on the internet. The actual insurance provider might often supply you discount, and this might help it will save you money in addition to that of your energy. Moreover, searching for the actual car insurance online may also be a convenient choice because if so, you would be able to do it right from your home anytime schedule. Nevertheless, you would need to carry out comprehensive research before buying them. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 04:42:55 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 04:42:55 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #246: Guidance Regarding Tents Message-ID: <047.f58f40d5fe1587fb8bff9f2cf1e0bef2@kirei.se> #246: Guidance Regarding Tents ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- Guidance Regarding Tents Along with [http://www.outdoorworld.co.uk tents] you also take some additional camping equipment like the [http://www.outdoorworld.co.uk [http://www.outdoorworld.co.uk/camping-equipment-sleeping- bags-c-33_50.html sleeping bags] when you're going for a camping. Therefore, you always must choose the best hiking things for you personally. It's very common that when you are getting free time from your workplace as well as your kids have vacations from schools you'll love to go for a hiking along with your loved ones. When you're taking a camping then your most important thing that you'll require is the camping tent. But it is extremely important that you know every moment detail concerning the camping tent. In the following paragraphs we now have decided to assist you to by providing a few ideas regarding how as well as what to consider in the event of selecting a camping tent. The first thing that you must keep in mind whilst selecting tents is that you must look for the correct size this. Because there are various designs, shapes and sizes of the tents so, it is a bit a hardship on regular individuals to obtain the best one. The first thing that you must think about is the fact that based on how lots of people you need the actual camping tent? If you are using the camping tent for a single individual then you definitely must obtain a tent that weighs 1-2.5kg. But for the tent that must definitely be employed for loved ones ought to weigh regarding One.75-5kgs. Another important thing to think about is the form of the actual camping tent. You need to select the form and fashions based on your focal points as well as space. You must also think about the supplies from the tents. Avoid individuals materials that induce pain and allergic reactions. The camping tent should be totally water-resistant and you should check that there are many films inside it. Correct air flow is actually should for the tents so you don't get suffocated within. You will find different brands of tents available for sale. You can visit various departmental stores as well as to the online retailers for the greatest 1. It is usually recommended to look for the best things on the net as you will get many selections and in addition it saves your time and money. For many hiking lovers the [http://www.outdoorworld.co.uk/tents-by- brand-coleman-tents-c-16_19.html Coleman tents] serve the best objective throughout the camping. They have all the necessary qualities that a great camping tent should have. They have a lot of advantages that individuals like to use them. They're not only easily available however, you will even find that they are greatly reasonable in cost. The people who have used them offers provided thumbs up with this brand name. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 05:07:57 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 05:07:57 -0000 Subject: [Opendnssec-develop] [OpenDNSSEC] #247: How to Choose an ideal Camping tent for You Message-ID: <047.8bf96164a0494fa7bcba4ccb72ce06e6@kirei.se> #247: How to Choose an ideal Camping tent for You ----------------------+----------------------------------------------------- Reporter: anonymous | Owner: rb Type: defect | Status: new Priority: major | Component: Unknown Version: trunk | Keywords: ----------------------+----------------------------------------------------- How to Choose an ideal Camping tent for You One of the biggest outdoor actions perhaps is actually camping. And when talking about hiking, [http://www.caseysoutdoorleisure.co.uk/ tents] would be the quantity concern. Hiking could be more enjoyable should you choose the right tent as well as hiking gear. In choosing the camping tent you will buy, be certain that you're conscious of the options you've in the market to be able to select the one which fits your needs. Basically, tents come in various sizes and designs. And you might end upward overcome with the quantity of choices that you have. Therefore, you need to narrow down your choices. It is recommended that you jot down particular requirements about the tent you prefer to make use of for the camping. Before you decide to move forward when choosing the tent you will buy or even bring, you have to consider the quantity of individuals who does be utilising the actual tent. Is it with regard to single make use of? Or you would rather stay within the tent like a team? You should also consider the location and duration of hiking when choosing the actual camping tent you would provide. A few of the well-known designs include geodesic, The post, nicely guyed tunnel as well as solitary hoop. You need to think about the scenario in the region. For example, if you are considering visit high level websites along with strong winds, you should look at bringing well guyed canal or geodesic types of tents. If you are aware of the colour, you need to choose it too. Through an appealing tent provides spice to your adventure. As for the particular types of tents, some of the most popular include [http://www.caseysoutdoorleisure.co.uk/vango-tents-28-c.asp Vango Tents] as well as [http://www.caseysoutdoorleisure.co.uk/cabanon-tents-305-c.asp Cabanon Tents]. Both of them offer innovative styles and features. Nevertheless, you need to identify your own real requirements because travelers that you should develop the best choice. If you're unaware, searching with regard to suggestions online which one would fit your camping ideas. Make sure to consider the tents??? performance and convenience besides the style as well as color. If you intend to go to higher level websites, getting overweight tents might not be suggested since they would be way too hard to transport. Bear all of these in your mind, and also you would not have condition in deciding on the ideal tent for your hiking. If you're adventurer that enjoys outdoor actions, investing on high-end as well as high quality tents would be worth it. -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 07:13:59 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 07:13:59 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #240: Remove $Id tags from configuration files In-Reply-To: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> References: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> Message-ID: <080.2b7e5dda9e80d1e61a1458e26f8319a1@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by rb): I get no diff: rickard at fou:~/softHSM/dnssec$ diff tags/OpenDNSSEC-1.2.1/conf/kasp.xml.in tags/OpenDNSSEC-1.3.0rc2/conf/kasp.xml.in rickard at fou:~/softHSM/dnssec$ -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 20 07:35:56 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 20 May 2011 07:35:56 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #240: Remove $Id tags from configuration files In-Reply-To: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> References: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> Message-ID: <080.a23683e0b07382f8197cee6cd9a839a0@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by Ond?ej Sur? ): You need to compare checked out versions. {{{ $ diff -urNap opendnssec-1.3.0rc1/conf/ opendnssec-1.3.0rc2/conf/ diff -urNap opendnssec-1.3.0rc1/conf//conf.rnc opendnssec-1.3.0rc2/conf//conf.rnc --- opendnssec-1.3.0rc1/conf//conf.rnc 2011-04-21 14:23:31.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//conf.rnc 2011-05-18 10:15:08.000000000 +0200 @@ -1,4 +1,4 @@ -# $Id: conf.rnc 4688 2011-04-07 13:58:21Z matthijs $ +# $Id: conf.rnc 4998 2011-04-21 12:29:27Z jakob $ # # Copyright (c) 2009 .SE (The Internet Infrastructure Foundation). # All rights reserved. diff -urNap opendnssec-1.3.0rc1/conf//conf.rng opendnssec-1.3.0rc2/conf//conf.rng --- opendnssec-1.3.0rc1/conf//conf.rng 2011-04-21 14:26:00.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//conf.rng 2011-05-18 10:19:11.000000000 +0200 @@ -1,6 +1,6 @@ + diff -urNap opendnssec-1.3.0rc1/conf//kasp.rnc opendnssec-1.3.0rc2/conf//kasp.rnc --- opendnssec-1.3.0rc1/conf//kasp.rnc 2011-04-21 14:23:31.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//kasp.rnc 2011-05-18 10:15:08.000000000 +0200 @@ -1,4 +1,4 @@ -# $Id: kasp.rnc 4027 2010-09-29 10:17:08Z sion $ +# $Id: kasp.rnc 4998 2011-04-21 12:29:27Z jakob $ # # Copyright (c) 2009 .SE (The Internet Infrastructure Foundation). # All rights reserved. diff -urNap opendnssec-1.3.0rc1/conf//kasp.rng opendnssec-1.3.0rc2/conf//kasp.rng --- opendnssec-1.3.0rc1/conf//kasp.rng 2011-04-21 14:26:01.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//kasp.rng 2011-05-18 10:19:12.000000000 +0200 @@ -1,6 +1,6 @@ + + + diff -urNap opendnssec-1.3.0rc1/conf//zonefetch.rnc opendnssec-1.3.0rc2/conf//zonefetch.rnc --- opendnssec-1.3.0rc1/conf//zonefetch.rnc 2011-04-21 14:23:31.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//zonefetch.rnc 2011-05-18 10:15:08.000000000 +0200 @@ -1,4 +1,4 @@ -# $Id: zonefetch.rnc 1920 2009-09-30 07:49:39Z matthijs $ +# $Id: zonefetch.rnc 4998 2011-04-21 12:29:27Z jakob $ # # Copyright (c) 2009 .SE (The Internet Infrastructure Foundation). # All rights reserved. diff -urNap opendnssec-1.3.0rc1/conf//zonefetch.rng opendnssec-1.3.0rc2/conf//zonefetch.rng --- opendnssec-1.3.0rc1/conf//zonefetch.rng 2011-04-21 14:26:02.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//zonefetch.rng 2011-05-18 10:19:12.000000000 +0200 @@ -1,6 +1,6 @@ + diff -urNap opendnssec-1.3.0rc1/conf//zonelist.rnc opendnssec-1.3.0rc2/conf//zonelist.rnc --- opendnssec-1.3.0rc1/conf//zonelist.rnc 2011-04-21 14:23:31.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//zonelist.rnc 2011-05-18 10:15:08.000000000 +0200 @@ -1,4 +1,4 @@ -# $Id: zonelist.rnc 1897 2009-09-29 12:40:20Z jakob $ +# $Id: zonelist.rnc 4998 2011-04-21 12:29:27Z jakob $ # # Copyright (c) 2009 .SE (The Internet Infrastructure Foundation). # All rights reserved. diff -urNap opendnssec-1.3.0rc1/conf//zonelist.rng opendnssec-1.3.0rc2/conf//zonelist.rng --- opendnssec-1.3.0rc1/conf//zonelist.rng 2011-04-21 14:26:01.000000000 +0200 +++ opendnssec-1.3.0rc2/conf//zonelist.rng 2011-05-18 10:19:12.000000000 +0200 @@ -1,6 +1,6 @@ + -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 27 07:56:00 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 27 May 2011 07:56:00 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #240: Remove $Id tags from configuration files In-Reply-To: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> References: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> Message-ID: <080.614f76db6da926e8866a668c19f5fb14@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by Ond?ej Sur? ): Then you are doing something wrong (freshly downloaded tarballs): {{{ ondrej at ki:/tmp/opendnssec$ ls -l total 4892 drwxr-xr-x 13 ondrej ondrej 4096 2011-05-27 09:52 opendnssec-1.2.1 -rw-r--r-- 1 ondrej ondrej 1649465 2011-03-18 16:14 opendnssec-1.2.1.tar.gz drwxr-xr-x 13 ondrej ondrej 4096 2011-05-27 09:52 opendnssec-1.3.0rc1 -rw-r--r-- 1 ondrej ondrej 1672044 2011-04-21 14:28 opendnssec-1.3.0rc1.tar.gz drwxr-xr-x 13 ondrej ondrej 4096 2011-05-27 09:52 opendnssec-1.3.0rc2 -rw-r--r-- 1 ondrej ondrej 1668777 2011-05-18 10:19 opendnssec-1.3.0rc2.tar.gz ondrej at ki:/tmp/opendnssec$ head -3 */conf/zonelist.xml.in ==> opendnssec-1.2.1/conf/zonelist.xml.in <== ==> opendnssec-1.3.0rc1/conf/zonelist.xml.in <== ==> opendnssec-1.3.0rc2/conf/zonelist.xml.in <== }}} As the only difference in the three files is: {{{ $ diff3 */conf/zonelist.xml.in ==== 1:3c 2:3c 3:3c }}} -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 27 08:31:57 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 27 May 2011 08:31:57 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #240: Remove $Id tags from configuration files In-Reply-To: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> References: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> Message-ID: <080.d497495501a62c6fe462b4e9238a21d3@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by rb): Ok, sorry. The tarball I had must have been created by me locally. I will check with Jakob and see how he create his tarballs. {{{ rickard at fou:~$ wget http://www.opendnssec.org/files/source/opendnssec-1.3.0rc2.tar.gz --08:28:39-- http://www.opendnssec.org/files/source/opendnssec-1.3.0rc2.tar.gz => `opendnssec-1.3.0rc2.tar.gz' Resolving www.opendnssec.org... 91.206.174.13 Connecting to www.opendnssec.org|91.206.174.13|:80... connected. HTTP request sent, awaiting response... 200 OK Length: 1,668,777 (1.6M) [application/x-gzip] 100%[==================================================================================================================>] 1,668,777 2.25M/s 08:28:40 (2.24 MB/s) - `opendnssec-1.3.0rc2.tar.gz' saved [1668777/1668777] rickard at fou:~$ tar -xzf opendnssec-1.3.0rc2.tar.gz rickard at fou:~$ head -3 opendnssec-1.3.0rc2/conf/zonelist.xml.in }}} -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 27 08:44:56 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 27 May 2011 08:44:56 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #240: Remove $Id tags from configuration files In-Reply-To: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> References: <065.d999458c6817b10e81d4259aa2c1fbec@kirei.se> Message-ID: <080.652be021de5bbe26766fca3ecbef0855@kirei.se> #240: Remove $Id tags from configuration files ------------------------------------------+--------------------------------- Reporter: Ond?ej Sur? | Owner: rb Type: enhancement | Status: new Priority: trivial | Component: Unknown Version: trunk | Resolution: Keywords: | ------------------------------------------+--------------------------------- Comment (by rb): The release was created from a tag that was not yet committed to the repository. {{{ (Pseudocode) svn copy trunk tag cd tag make dist svn ci }}} will in future releases be changed to {{{ (Pseudocode) svn copy trunk tag svn ci cd tag make dist }}} -- Ticket URL: OpenDNSSEC OpenDNSSEC From owner-dnssec-trac at kirei.se Fri May 27 09:42:51 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Fri, 27 May 2011 09:42:51 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #192: Minor feature: key label logging upon HSM deletion In-Reply-To: <045.f1bef3ee2517c2ccc719ef1b1e1cdb6f@kirei.se> References: <045.f1bef3ee2517c2ccc719ef1b1e1cdb6f@kirei.se> Message-ID: <060.0f26d807ff160f073c389e5ed18cb852@kirei.se> #192: Minor feature: key label logging upon HSM deletion ------------------------+--------------------------------------------------- Reporter: vanrein | Owner: sion Type: enhancement | Status: new Priority: trivial | Component: Enforcer Version: | Resolution: Keywords: | ------------------------+--------------------------------------------------- Comment (by jakob): Please do. -- Ticket URL: OpenDNSSEC OpenDNSSEC From rickard at opendnssec.org Mon May 30 07:22:35 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 30 May 2011 09:22:35 +0200 Subject: [Opendnssec-develop] Converting unsigned data to lowercase In-Reply-To: References: <4DDE5DAB.8050000@nlnetlabs.nl> Message-ID: .SE will in the June release remove the uppercase data. This will thus not be a problem. On Fri, May 27, 2011 at 8:21 AM, Rickard Bellgrim wrote: > I cannot remember if we modified the 1.0 code in trunk or if .SE had > an internal patch. But I think the solution was to canonicalize the > data just before signing and not when data was written to the internal > storage. Keeping in mind that sorting should ignore the character > case. > > RFC4343 also mention that you should not modify the character case of > the input data: > > ****** > 4.2. ?DNS Input Case Preservation > > ? Originally, DNS data came from an ASCII Master File as defined in > ? [STD13] or a zone transfer. ?DNS Dynamic update and incremental zone > ? transfers [RFC1995] have been added as a source of DNS data [RFC2136, > ? RFC3007]. ?When a node in the DNS name tree is created by any of such > ? inputs, no case conversion is done. ?Thus, the case of ASCII labels > ? is preserved if they are for nodes being created. > ****** > > > On Thu, May 26, 2011 at 4:03 PM, Matthijs Mekking wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I remember that one of the possible solutions was to store the input >> data next to the ldns rr so-to-say. Use the canonicalized ldns rr for >> creating signatures and use the untouched input data for writing the >> signed zone file. >> >> This has not been done yet. It was I believe low priority. Plus, it >> pushes even more on our memory usage. >> >> The other option was to fix your script:). Domain name comparison should >> be case insensitive. >> >> Best regards, >> >> Matthijs >> >> >> On 05/26/2011 03:49 PM, Rickard Bellgrim wrote: >>> Hi >>> >>> Currently I am setting up v1.3.0 in our test bed, but .SEs test >>> scripts will not accept the signed zone because all of the uppercase >>> data has been converted to lowercase. It is around 500 RR where the >>> domain name is written in uppercase. (This is some old data in the >>> database, new data will be saved in lowercase) >>> >>> I remember that we had this discussion more than a year ago and we >>> ended up changing the behavior of the Signer Engine to not touch the >>> data and only do the conversion on the input for the signatures. >>> >>> What is our opinion this time? >>> >>> // Rickard >>> _______________________________________________ >>> Opendnssec-develop mailing list >>> Opendnssec-develop at lists.opendnssec.org >>> https://lists.opendnssec.org/mailman/listinfo/opendnssec-develop >> >> -----BEGIN PGP SIGNATURE----- >> Version: GnuPG v1.4.11 (GNU/Linux) >> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ >> >> iQEcBAEBAgAGBQJN3l2qAAoJEA8yVCPsQCW5Nk8IALsrwWk78hQCf42hjl1BVoFe >> wPQpETO735NgrlW2KoAPAbGS3/Q25WIp50bpP2WWAZQJdcfAcIO0c+OgLRpPjAha >> XKY1hnnbUqgU90MwOJlktz45Xb8+5JZC9/Mia8AlMR/2ERFkY1VReXTQuioB9slT >> OVBD7magkuLxe3OHITMoF3jb7o96Sfb8aD5tUAFHKBHYqoG4MPZMATlTJj80Fzpg >> sLSrtQ7uU2rpDJfbm3vHeShnfUpnLOtMumAUkKlaqq0XKZvyqoCC+gz1sR+Fkd9V >> M0jbfXxr73Nakdp0VALU2mePN2eIc1eeexo3xQYFsHIbMOKEN7iZOSjlP7SFZo0= >> =D8kK >> -----END PGP SIGNATURE----- >> > From rickard at opendnssec.org Mon May 30 07:45:43 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 30 May 2011 09:45:43 +0200 Subject: [Opendnssec-develop] States and rollovers in Enforcer NG Message-ID: Hi Is it possible to get summarized view of the key state and what action is needed by the user, e.g. send DS to parent. Or when the next rollover is expected? Now you do not know if the key is considered as active or not. rickard at fou:~$ sudo ods-enforcer key list Database set to: /home/rickard/opendnssec/enforcer.db Keys: Zone: Key role: DS: DNSKEY: RRSIG: Id: se CSK omnipresent omnipresent omnipresent se KSK hidden hidden hidden 0dd22611b195498cfec46978b9e5f59f se ZSK hidden unretentive omnipresent 9e82219991053ae81c1dfeaca582b74f se ZSK hidden rumoured omnipresent d784a99721c744d500f4868413e9c4c7 key list completed in 0 seconds. From yuri at NLnetLabs.nl Mon May 30 08:56:45 2011 From: yuri at NLnetLabs.nl (Yuri Schaeffer) Date: Mon, 30 May 2011 10:56:45 +0200 Subject: [Opendnssec-develop] States and rollovers in Enforcer NG In-Reply-To: References: Message-ID: <4DE35BCD.5000901@nlnetlabs.nl> Hi Rickard, > Is it possible to get summarized view of the key state and what action > is needed by the user, e.g. send DS to parent. Or when the next > rollover is expected? A rollover is a more organic process now. Currently you can get an indication of the first required 'action' for this zone with "ods-enforcer zone list". It's not specified what this action will be in advance. What we could do is give the time when the policy dictates a new key is required and will be inserted, but I have to talk to Rene about the interface. Does this sound useful? "key ds-submit" indicates which DS records should be submit to the parent. with "key ds-seen" the user can indicate / view he did in fact submit it. > Now you do not know if the key is considered as active or not. I just added two columns to key list indicating that. It is literally what will be written in the signer configuration. //Yuri -- Yuri Schaeffer NLnet Labs http://www.nlnetlabs.nl From rickard at opendnssec.org Mon May 30 11:40:22 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 30 May 2011 13:40:22 +0200 Subject: [Opendnssec-develop] States and rollovers in Enforcer NG In-Reply-To: <4DE35BCD.5000901@nlnetlabs.nl> References: <4DE35BCD.5000901@nlnetlabs.nl> Message-ID: On Mon, May 30, 2011 at 10:56 AM, Yuri Schaeffer wrote: > Hi Rickard, > >> Is it possible to get summarized view of the key state and what action >> is needed by the user, e.g. send DS to parent. Or when the next >> rollover is expected? > > A rollover is a more organic process now. Currently you can get an > indication of the first required 'action' for this zone with > "ods-enforcer zone list". It's not specified what this action will be in > advance. Is this basically the item that should be scheduled in the queue? Currently the queue is empty. > What we could do is give the time when the policy dictates a new key is > required and will be inserted, but I have to talk to Rene about the > interface. Does this sound useful? Yes, because then you know when future key rollovers will happen. > "key ds-submit" indicates which DS records should be submit to the > parent. with "key ds-seen" the user can indicate / view he did in fact > submit it. The ZSKs are now included in that list. Do we need to have them there? >> Now you do not know if the key is considered as active or not. > > I just added two columns to key list indicating that. It is literally > what will be written in the signer configuration. Thanks, this made it easier to see the state of the zone. From rickard at opendnssec.org Mon May 30 14:32:54 2011 From: rickard at opendnssec.org (Rickard Bellgrim) Date: Mon, 30 May 2011 16:32:54 +0200 Subject: [Opendnssec-develop] Enforcer NG branch Message-ID: Should I clean up the build scripts and remove the old Enforcer from the Enforcer NG branch? From jakob at kirei.se Mon May 30 14:59:11 2011 From: jakob at kirei.se (Jakob Schlyter) Date: Mon, 30 May 2011 16:59:11 +0200 Subject: [Opendnssec-develop] Enforcer NG branch In-Reply-To: References: Message-ID: <0C2AEFE8-B0D7-4CA6-A112-19EF29D115E2@kirei.se> On 30 maj 2011, at 16.32, Rickard Bellgrim wrote: > Should I clean up the build scripts and remove the old Enforcer from > the Enforcer NG branch? Unless that makes pull-up from trunk harder, I'm all for it. jakob From owner-dnssec-trac at kirei.se Mon May 30 23:17:18 2011 From: owner-dnssec-trac at kirei.se (OpenDNSSEC) Date: Mon, 30 May 2011 23:17:18 -0000 Subject: [Opendnssec-develop] Re: [OpenDNSSEC] #192: Minor feature: key label logging upon HSM deletion In-Reply-To: <045.f1bef3ee2517c2ccc719ef1b1e1cdb6f@kirei.se> References: <045.f1bef3ee2517c2ccc719ef1b1e1cdb6f@kirei.se> Message-ID: <060.b49f8f9b58702c7387b283664340cfec@kirei.se> #192: Minor feature: key label logging upon HSM deletion ------------------------+--------------------------------------------------- Reporter: vanrein | Owner: sion Type: enhancement | Status: new Priority: trivial | Component: Enforcer Version: | Resolution: Keywords: | ------------------------+--------------------------------------------------- Comment (by Sebastian Castro ): Attached patch to print messages like ods-enforcerd: Key 2bdcaf7ff2049bae6ce5e5be119a60f0 removed successfully when enforcerd purges key. The same applies when purging is done using ods-ksmutil. The format of the message is different from ods-hsmutil (which uses "Key remove successful: "). If you think all messages should be consistent, I can make the changes to have them all aligned. -- Ticket URL: OpenDNSSEC OpenDNSSEC