[Opendnssec-user] ods-ksmutil zone delete doesn't clean after itself

Matthijs Mekking matthijs at NLnetLabs.nl
Mon Oct 11 08:59:47 UTC 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 10/08/2010 02:22 PM, Rickard Bellgrim wrote:
>> My understanding is if you add the same zone later with different
>> contents (and possibly with different keys), this might create an
>> inconsistency?
> 
> 
> I pass this question to Matthijs.

The signer gets confused if there still exists a signed zonefile in the
output directory. It will continue resigning the previous known zone
with the previous known signer configuration.

This can be avoided, before re-adding the zone, by remove the signed
zone from the output directory.

Best regards,

Matthijs
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJMstIDAAoJEA8yVCPsQCW5xcgIALqRIrgJ3jA6mM0ksx0vCcmZ
DMaCO5jipAsZcpNl2mwuAMqM9jvuink1hb58PP5UUQPVYfnZ/GFW2nh8BUtjSXb+
UbR6SyhuwlAoeJxc+6DeafyEp6g9zOGhv2If5UE1pITwRBM8bi/zQ5YH+Fzxxpf3
0ZZhC2IDoKMCLbpn+ALaSwS+ODbpnyXYko754zYcYOXccgiBQ/fMiKVbDhXqGEP4
qi/ZFihnuzVvmv9tWgMyWl1h9y6t8TTZC/07R7gZBbNK6eSBI4JnRWJ4cCQYrcQw
UW7X1SLtBZwcmJb3dIt7wpZFdciL8MP9JtzYsI2Z+u2Hf/w5VwqJRAyl6M6hCAg=
=ZJHI
-----END PGP SIGNATURE-----



More information about the Opendnssec-user mailing list