[Opendnssec-user] Not enough keys to satisfy zsk policy for zone

Marc Richter marc.richter at de.verizon.com
Wed Dec 20 14:21:25 UTC 2017


Hi,

> Then you have a different problem. Please check which user OpenDNSSEC
> runs as and make sure that your HSM allows that user write access.

I checked that already. The user that runs ODS does have read/write access
to the SoftHSM storage directory (actually the token directory is owned by
the user that runs ODS).
I could successfully create and delete files with that userid in the HSM
storage directory.

Using that userid I can also run ods-hsmutil to list keys etc.

Regards
Marc

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20171220/b015d6c9/attachment.bin>


More information about the Opendnssec-user mailing list