[Opendnssec-user] Rollover: DNSKEY for old KSK gone from signed zone before issuing ds-seen/ds-gone commands

Yuri Schaeffer yuri at nlnetlabs.nl
Mon Jan 8 11:35:46 UTC 2018


> Now I'm wondering why this happens and if this might be a bug in
> OpenDNSSEC.

Given your previous mail I think you've hit a bug. There is code
handling rollovers with N keys. This case should be covered but it is
rather complex and thus likely the culprit. I'll take a look. Thanks for
reporting!

//Yuri

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20180108/1f2f5712/attachment.bin>


More information about the Opendnssec-user mailing list