Re: [Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Pieter Lexis
Hi Eric, On Wed, 8 Nov 2017 16:53:49 -0500 Eric Beck wrote: (Pushing this mail back to the mailing list) > So then my understanding is that inception days are written in stone, > for all pdns servers worldwide, and that it is a server calculated date > based on Thursdays since the epoch event.

Re: [Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Pieter Lexis
Hi Eric, On Wed, 8 Nov 2017 14:47:36 -0500 Eric Beck wrote: > As per the docs, > "RRSIGs have a validity period, in PowerDNS this period is 3 weeks. This > period starts at most a week in the past, and continues at least a week > into the future" > > As well the first domain we secured was done

Re: [Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Eric Beck
Oops, I had digest set and didn't realize ... couldn't see replies unless on web at pdns-users Ok, sorted out that, and will get replies directly now too. I have read both replies, and I did read that section of the docs but that is in part what is confusing. If the start date is supposed to be

Re: [Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Pieter Lexis
Hi Eric and Peter, On Wed, 8 Nov 2017 18:03:01 +0100 Peter Thomassen wrote: > On 11/08/2017 05:59 PM, Eric Beck wrote: > > What I don't understand, is that this particular domain we just secured > > today. The RRSIG expiry is 16 Nov. and it says the valid from is Oct. 26. > > > From the las

Re: [Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Peter Thomassen
Hi Eric, On 11/08/2017 05:59 PM, Eric Beck wrote: > What I don't understand, is that this particular domain we just secured > today. The RRSIG expiry is 16 Nov. and it says the valid from is Oct. 26. From the last sub-section of https://doc.powerdns.com/md/authoritative/dnssec/#online-signing (n

[Pdns-users] trying to understand pdns and dnssec

2017-11-08 Thread Eric Beck
Hello All, New at PowerDNS. Implemented pdns Centos 7, native mysql setup. MariaDB 10.2.10, PowerDNS 4.1rc2 We are using .ca domains for testing. We have run pdnsutil secure-zone ZONE on two domains now with success after submitting DNSKEY+DS(sha256) to CIRA. My question is concerning key roll