Re: KSK signing incomplete

2014-05-21 Thread Klaus Darilion
On 21.05.2014 12:39, Phil Mayers wrote: > On 21 May 2014 10:24:23 BST, Klaus Darilion > wrote: >>> Further, I see that sometimes there are no private records at all. >> When >>> does this happen? (I never called "rndc signing -clear") >> >> It seems that this happens when Bind is restarted. >>

Re: KSK signing incomplete

2014-05-21 Thread Phil Mayers
On 21 May 2014 10:24:23 BST, Klaus Darilion wrote: >> Further, I see that sometimes there are no private records at all. >When >> does this happen? (I never called "rndc signing -clear") > >It seems that this happens when Bind is restarted. > >So, what is the suggested (and reliable) way for ext

Re: KSK signing incomplete

2014-05-21 Thread Klaus Darilion
> Further, I see that sometimes there are no private records at all. When > does this happen? (I never called "rndc signing -clear") It seems that this happens when Bind is restarted. So, what is the suggested (and reliable) way for external tools to get the signing status from Bind? I.e. if a k

KSK signing incomplete

2014-05-20 Thread Klaus Darilion
Hi! Using Bind 9.9.5. I have some questions about the private records which indicate the signing status. From my external key management and monitoring tool I query the private records to get the signing status, e.g. if the signing after a rollover is finished, if a key can be deleted from disk,