* Daniel Kahn Gillmor [2017-10-19 15:44:40 -0400]: > However, i'm not convinced that dnssec-dsfromkey is at fault, because i > think the versions of dnssec-dsfromkey in stretch and buster both have > the same behavior.
It turns out the following change from version 2017020200 of the package was not included in the jessie backport: * Rewrite DS creation check to xml2 and ldnsutils, as neither xmllint nor bind9utils handle multiple DNSKEY in one file correctly