Indeed. I imported the key and got a .key and .private file. I put those files in the same directory as the other keys, gave read permissions to bind and executed:So, how is the correct process to add an additional DNSKEY (only the publickey is known).
I think you are looking for `dnssec-importkey`.
So, how is the correct process to add an additional DNSKEY (only the public >> key is known).
I think you are looking for `dnssec-importkey`.
Indeed. I imported the key and got a .key and .private file. I put those files in the same directory as the other keys, gave read permissions to bind and executed:
rndc loadkeys myzone
rndc sign myzone
But the additional key is not added to the reponse of DNSKEY queries.
On 09.07.20 11:51, Klaus Darilion wrote:
So, how is the correct process to add an additional DNSKEY (only the publickey is known).
I think you are looking for `dnssec-importkey`.
Indeed. I imported the key and got a .key and .private file. I put thosefiles in the same directory as the other keys, gave read permissions to
bind and executed:
rndc loadkeys myzone
rndc sign myzone
But the additional key is not added to the reponse of DNSKEY queries.
Does the key have correct timing metadata in the key file?
Have a look at "dnssec-settime".
Sysop: | DaiTengu |
---|---|
Location: | Appleton, WI |
Users: | 991 |
Nodes: | 10 (0 / 10) |
Uptime: | 81:04:10 |
Calls: | 12,949 |
Calls today: | 3 |
Files: | 186,574 |
Messages: | 3,264,663 |