[Opendnssec-user] Key state not changing at "Date of next transition"

Berry A.W. van Halderen berry at nlnetlabs.nl
Wed May 4 07:13:56 UTC 2016


On 05/04/2016 08:59 AM, Arun N S wrote:
> Hi,
> 
>  Trying to configure OpenDNSSEC with SoftHSM with automatic key
> generation and roll over.  
> 
>  While querying the database for keys:
> Zone:                           Keytype:      State:    Date of next
> transition (to):  Size:   Algorithm:  CKA_ID:                          
> Repository:                       Keytag:
> example.com <http://example.com>               ZSK           active  
>  2016-05-04 10:40:56 (retire)   2048    8          
> 457a1480ae07d5a966d40338777e4b93  SoftHSM                           31461
> example.com <http://example.com>               ZSK           generate
>  (not scheduled)     (publish)  2048    8          
> 5ab3b8b52447860557e3b47c0c3b0ac8  SoftHSM                           23151
> example.com <http://example.com>               KSK           publish  
> 2016-05-04 09:47:36 (ready)    2048    8          
> 2fcc6fb8591261b35d82b81f588b630d  SoftHSM                           45250
> 
>  I can see that "Date of next transition" for KSK is at  2016-05-04
> 09:47:36  to READY. Is it supposed to happen automatically? 

Yes, as long as the system is running transitions are performed
automatically.  Except when it explicitly indicates so ("waiting
for...").

> The state did not change until I stop and start ods-control.

How do you mean, the transition is scheduled for a future time (at least
I guess your timezone).  Was the state different earlier or did
it change state?

\Berry

> Thanks,
> Arun
> 
> 
> 
> _______________________________________________
> Opendnssec-user mailing list
> Opendnssec-user at lists.opendnssec.org
> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
> 




More information about the Opendnssec-user mailing list