[Opendnssec-user] Key state not changing at "Date of next transition"
Berry A.W. van Halderen
berry at nlnetlabs.nl
Wed May 4 07:13:56 UTC 2016
On 05/04/2016 08:59 AM, Arun N S wrote:
> Hi,
>
> Trying to configure OpenDNSSEC with SoftHSM with automatic key
> generation and roll over.
>
> While querying the database for keys:
> Zone: Keytype: State: Date of next
> transition (to): Size: Algorithm: CKA_ID:
> Repository: Keytag:
> example.com <http://example.com> ZSK active
> 2016-05-04 10:40:56 (retire) 2048 8
> 457a1480ae07d5a966d40338777e4b93 SoftHSM 31461
> example.com <http://example.com> ZSK generate
> (not scheduled) (publish) 2048 8
> 5ab3b8b52447860557e3b47c0c3b0ac8 SoftHSM 23151
> example.com <http://example.com> KSK publish
> 2016-05-04 09:47:36 (ready) 2048 8
> 2fcc6fb8591261b35d82b81f588b630d SoftHSM 45250
>
> I can see that "Date of next transition" for KSK is at 2016-05-04
> 09:47:36 to READY. Is it supposed to happen automatically?
Yes, as long as the system is running transitions are performed
automatically. Except when it explicitly indicates so ("waiting
for...").
> The state did not change until I stop and start ods-control.
How do you mean, the transition is scheduled for a future time (at least
I guess your timezone). Was the state different earlier or did
it change state?
\Berry
> Thanks,
> Arun
>
>
>
> _______________________________________________
> Opendnssec-user mailing list
> Opendnssec-user at lists.opendnssec.org
> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
>
More information about the Opendnssec-user
mailing list