[Opendnssec-user] RRSIG for hobby.nl expires soon

Bas van den Dikkenberg bas at dikkenberg.net
Wed Jul 4 16:08:38 UTC 2012


I don't think this jitter isue.

Because the rrsig wil expire tomorrow, so the even with the jitter the rrsig sould be resigned 1,5 day ago right ?


-----Oorspronkelijk bericht-----
Van: opendnssec-user-bounces at lists.opendnssec.org [mailto:opendnssec-user-bounces at lists.opendnssec.org] Namens Scott Armitage
Verzonden: woensdag 4 juli 2012 17:27
Aan: Miek Gieben
CC: <opendnssec-user at lists.opendnssec.org>
Onderwerp: Re: [Opendnssec-user] RRSIG for hobby.nl expires soon


On 4 Jul 2012, at 16:19, Miek Gieben wrote:

> [ Quoting <bas at dikkenberg.net> in "[Opendnssec-user] RRSIG for hobby.n..." ]
>> Hi i have problem with rrsig's that are expiring.
>> 
>> In the kaspl it states that the rrsig's must be refresh 3d before they expire.
>> 
>> But opendnssec doesn't refresh them.
> 
> isn't the jitter also in play here? I.e. In the worst case they expire
> 3 +12 hours day


I thought of that.  But even including the jitter, I had signatures which were well outside of the time when they should have been refreshed.  As previously mentioned I've been too busy to look into it, and wasn't overly concerned as ODS never let any signatures expire.  


Scott



More information about the Opendnssec-user mailing list