Re: Recently started invalid signings

2024-11-29 Thread Peter 'PMc' Much
On Fri, Nov 29, 2024 at 04:46:26PM +1100, Mark Andrews wrote: ! Looks like when we added the code to sign CDNSKEY and CDS with KSKs we missed ! code to skip REVOKED KSKs. Okay, happens. ! P.S. You have a DS pointing to a non self signed DNSKEY. Yes, probably, due to continuous-rollover. DS are m

Re: Recently started invalid signings

2024-11-28 Thread Mark Andrews
Looks like when we added the code to sign CDNSKEY and CDS with KSKs we missed code to skip REVOKED KSKs. P.S. You have a DS pointing to a non self signed DNSKEY. > On 29 Nov 2024, at 13:54, Peter 'PMc' Much > wrote: > > Hi, > > I just noticed my dns-signer recently started to create some >

Recently started invalid signings

2024-11-28 Thread Peter 'PMc' Much
Hi, I just noticed my dns-signer recently started to create some invalid signings - the two red arrows in here: https://dnsviz.net/d/daemon.contact/Z0ka0A/dnssec/ There is a history, one can go back and see these weren't present in March '24 and earlier. The problem is, I didn't change an