From he at uninett.no Wed Jan 8 14:48:31 2025 From: he at uninett.no (Havard Eidnes) Date: Wed, 08 Jan 2025 15:48:31 +0100 (CET) Subject: [Opendnssec-user] Adhering to RFC 9276 Sec. 3.1 In-Reply-To: <92919214-cef6-4c02-9806-29a3fb90e90b@prado.it> References: <92919214-cef6-4c02-9806-29a3fb90e90b@prado.it> Message-ID: <20250108.154831.1237094079864457436.he@uninett.no> >> I've been trying to set OpenDNSSEC to generate the NSEC3 parameter >> with an empty salt and zero iterations (as per RFC 9276 Sec. 3.1), but >> to no avail. I have tried setting to zero as well as >> length parameter, but couldn't get it working. >> Could some kind angel help me out here, please? > > hi, > > > > 1 > 0 > > > > > then apply the policy and wait Hm, in my case I also needed to manually do "ods-enforcer resalt" before the new salt would be applied, despite waiting over the holiday period. Luckily, the old salt value was old enough that it got replaced. Regards, - H?vard