[Opendnssec-user] Date of next transition: now

Yuri Schaeffer yuri at nlnetlabs.nl
Mon Apr 24 11:18:39 UTC 2017


Hi Sebastian,

> So it seems that there is some sort of problem while transitioning
> between states? Any idea what is going on?

Yes, I think you had a standby key in your 1.4 setup. 2.1 doesn't know
about this. It is not really doing a KSK rollover but it just so happens
to have to KSKs and it is coping with that. To solve this start a KSK
rollover:

ods-enforcer key rollover -z 6v6.de -t KSK

This should introduce a new key while also marking the two existing keys
as old. They will then be replaced by the new key.

//Yuri

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20170424/ddeb7e36/attachment.bin>


More information about the Opendnssec-user mailing list