[Opendnssec-user] Not enough keys to satisfy ksk policy for...

Sion Lloyd sion at nominet.org.uk
Wed Sep 1 15:15:12 UTC 2010


> some weeks ago, there was some mails concerning this problem : Not
> enough keys to satisfy ksk policy for zone:
> 
> I'm still suffering from this even after having upgraded from ODS 1.1.1 to
> 1.1.2.
> 
> So, I just come here to get some news about this issue.

Hi there.

The first time we saw this the work around was to generate some extra keys on 
the policy. In certain circumstances this fixes the issue.

More recently we have managed to reproduce this consistently by removing all 
zones from a policy and then putting some back on to it. this gets you into a 
situation where generating extra keys does not help.

A fix for this has been written and is currently being tested.

Sion



More information about the Opendnssec-user mailing list