[Opendnssec-user] Not enough keys to satisfy zsk policy for zone

Yuri Schaeffer yuri at nlnetlabs.nl
Thu Dec 21 12:06:57 UTC 2017


Hi Marc,

> The only thing I found is in the startup messages, where it says that "No
> new ZSKs need to be created".

This is a useful hint. We have two options. Either the number of 'still
good' keys from the database is counted wrong. Or the keys in the
database are in a strange state.

Perhaps a little bit of both. I'd like to dig in your database to see
which one. Can you send me a database dump? Your kasp.xml would also be
useful.

//Yuri

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20171221/008e593c/attachment.bin>


More information about the Opendnssec-user mailing list