[Opendnssec-user] Little Problems with OpenDNSSEC

Craig Whitmore lennon at orcon.net.nz
Wed Jun 22 07:28:50 UTC 2011

On 22/06/11 6:40 PM, "Rickard Bellgrim" <rickard at opendnssec.org> wrote:

>On Wed, Jun 22, 2011 at 1:17 AM, Craig Whitmore <lennon at orcon.net.nz>
>> But the KSK is not active..
>> ods-ksmutil key list
>> SQLite database set to: /var/lib/opendnssec/db/kasp.db
>> Keys:
>> Zone:                           Keytype:      State:    Date of next
>> transition:
>> spam.co.nz                      KSK           publish   2011-06-23
>> spam.co.nz                      ZSK           active    2011-07-22
>> So no DS's show..
>The KSK must first propagate. The date of next transition is
>2011-06-23 00:58:28. It will then be ready. The Enforcer will then
>wait for you to upload the DS and give back the ds-seen.
>// Rickard

Ok .. I understand.. Is there anyway to make the KSK active like the ZSK
is when the domain is initially added?



More information about the Opendnssec-user mailing list