[Opendnssec-develop] Key pregeneration count

Yuri Schaeffer yuri at nlnetlabs.nl
Thu Jul 12 09:19:01 UTC 2012


I took a look at the number of pregenerated keys on setup. This is how
the enforcer works:

- User can manually issue command to generate keys for duration X.
	ods-enforcer hsm key gen --duration X
	It will generate for all policies
- at setup keys are pregenerated. Interval is configured in conf.xml
	<KeygenInterval>P1Y</KeygenInterval>

This should be workable however it seems odd that both options are not
policy specific.



More information about the Opendnssec-develop mailing list