[Opendnssec-user] Re: New installation notes for Ubuntu (Beta5)

Rickard Bellgrim rickard.bellgrim at iis.se
Mon Nov 2 16:22:51 UTC 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Thanks for your guide.

Here are some of my comments.

No need for this if you run from the tarball:
        ~# apt-get install subversion
        ~# apt-get install autoconf
        ~# apt-get install automake
        ~# apt-get install libtool
        ~# apt-get install sun-java6-jre sun-java6-plugin sun-java6-fonts

This:
        ~# wget http://rubyforge.org/frs/download.php/65630/dnsruby-1.39.gem
        ~# sudo gem install /usr/local/bin/dnsruby-1.39.gem
Is equal to:
        ~# gem install dnsruby

OpenDNSSEC default to these settings, so they are not needed:
        --sysconfdir=/etc --localstatedir=/var

Botan is not installed here:
        --with-botan=/usr/local/bin
but here (which is default)
        --with-botan=/usr/local

LDNS is not installed here:
        --with-ldns=/usr/local/bin
but here (which is default)
        --with-ldns=/usr/local

Are you sure that you want to install SoftHSM here:
        --prefix=/usr/local/bin/softhsm
and not here (then will your system find e.g. the softhsm tool and no need to change directory later on):
        --prefix=/usr/local

No need for:
        ~# export SOFTHSM_CONF=/etc/softhsm.conf
        ~# echo $SOFTHSM_CONF
The default location is this. SOFTHSM_CONF is for when you want to have the config in another location.

The work-around when initializing the token is not needed since you have installed 1.9.0.

The token table gives you no useful information. It only shows you the token label and the digested SO and user PIN. You probably want to have a look in the Attribute table. One question, why do you want to have a look in the token database? Why not use the PKCS#11 interface to check for information?

You do not need to generate the keys yourself. The system will do that for you.

More information can be found on http://trac.opendnssec.org/wiki/Signer/Using

// Rickard

> -----Ursprungligt meddelande-----
> Från: opendnssec-user-bounces at lists.opendnssec.org [mailto:opendnssec-
> user-bounces at lists.opendnssec.org] För Rick Zijlker
> Skickat: den 2 november 2009 15:55
> Till: opendnssec-user at lists.opendnssec.org
> Ämne: [Opendnssec-user] New installation notes for Ubuntu (Beta5)
>
> Hey all,
>
>
>
> During installing OpenDNSSEC on my Ubuntu image I encountered several
> issues and I made note of these issues. Right now OpenDNSSEC (beta 5)
> is successfully signing here and I would like to share my notes with
> everyone to offer an easy checklist of all dependencies and possible
> issues plus solutions. It won’t win any beauty contests but it could be
> helpful for some of you.
>
>
>
> Some extra options like extra slots in softhsm are also described in
> this note.
>
>
>
> Cheers,
>
> Rick Zijlker


-----BEGIN PGP SIGNATURE-----
Version: 9.8.3 (Build 4028)
Charset: utf-8

wsBVAwUBSu8HW+CjgaNTdVjaAQh3kAgAiEMiJdu9SdCDlxTkEQeIINt+ZJmx2wqj
QLDj1yf0zPaxjDbAE/mAJSmdb+PAUi7NCy/V29idW4DqnZUmpJoxFOFeXtpBMg6f
qMpx3RPXm43iDz1XxST9KWM7q+EsS85MftCjQ5f6WeZr8FGVNKPp4GGE1x/ey3YV
PQHFP7cspOlgxBB3juDOqEKe+Ag9OLXZUioPLXcirmDX/RoyAs6K0pIKbz7r4TWB
JRAR3boJ28kslfcFXRGATDMhXMeUa9JXgZlMS4J6c6KAN2i4wYuXfIxPUHAGl+yu
8cubIIlp/TUXDRLDkc4i1azz+1hoeqSaUYJ/lG+MCKaS6ayWd2HrUQ==
=w2e+
-----END PGP SIGNATURE-----


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20091102/73295ad9/attachment.htm>


More information about the Opendnssec-user mailing list