[Opendnssec-user] Re: enforcer-ng produces suspicious number of ZSKs

Yuri Schaeffer yuri at nlnetlabs.nl
Thu Mar 13 10:34:53 UTC 2014


Woops, my reply did not make it to the list. Take 2:

> As a side-effect, I have found another bug (I guess):
> I have terminated ods-enforcer from the previous example with SIGINT
> (Ctrl+C) because I was impatient and not willing to wait for 2190 new
ZSKs.

I suppose you pulled it from our Git repository recently, can you tell
me what commit you are on? About a week ago some code was committed [0]
touching relevant code.

I think what is happening is that on startup the enforcer-ng will
restart filling its pool of pregenerated keys. I suppose at that time
you did not change the <AutomaticKeyGenerationPeriod> yet?

Regards,
//Yuri

[0]
https://github.com/opendnssec/opendnssec/commit/20c4fa58c00b42d88c84a9ae4efcc23cd6c898ce



More information about the Opendnssec-user mailing list