On 4/25/2013 11:57 AM, Evan Hunt wrote:
The warning is spurious and has been fixed in 9.9.3. It was incorrectly
checking to see whether there were any DNSKEY records in the zone *before*
loading them from the key files. It should have been doing so afterward,
obviously.
Ah, okay, thanks for
> dnssec-signzone -d /path/to/dsset -K /path/to/keys -3 00 -f
> zone.signed -e +3024000 -j 1800 -o zone.edu -r /dev/urandom -S -T 12h
> /path/to/input
>
> dnssec-signzone: warning: NSEC3 generation requested with no DNSKEY;
> ignoring
> Fetching ZSK 59544/RSASHA25
sec-signzone -d /path/to/dsset -K /path/to/keys -3 00 -f
zone.signed -e +3024000 -j 1800 -o zone.edu -r /dev/urandom -S -T 12h
/path/to/input
dnssec-signzone: warning: NSEC3 generation requested with no DNSKEY;
ignoring
Fetching ZSK 59544/RSASHA256 from key repository.
Fetching ZSK
3 matches
Mail list logo