[Opendnssec-develop] Enforcer NG kasp policy checks

Jerry Lundström jerry at opendnssec.org
Thu Aug 9 08:33:55 UTC 2012

Hi all,

This is interesting, as I'm trying to get the tests running on
Enforcer NG I just got:

Aug  9 10:18:36 debian64-ods01 ods-enforcerd: [enforcer] updatePolicy
Key lifetime unreasonably short with respect to TTL and MaxZoneTTL.
Will not insert key!

This policy works on 1.3/1.4.

Do we know how much more strict the NG is on the policies and if it
will affect our users?

Or is this maybe that MaxZoneTTL is new and does not have a default value?


More information about the Opendnssec-develop mailing list