> 2) ods-ksmutil key generate --policy=lab --interval P30D Just a comment: You do not need to generate the keys manually, OpenDNSSEC will do that for you (on the fly). But perhaps you do want to pre-generate keys, then this is the correct thing to do. // Rickard