bind9/bin/tests/system/kasp/ns6
Matthijs Mekking 63edc4435f Fix wrong usage of safety intervals in keymgr
There are a couple of cases where the safety intervals are added
inappropriately:

1. When setting the PublishCDS/SyncPublish timing metadata, we don't
   need to add the publish-safety value if we are calculating the time
   when the zone is completely signed for the first time. This value
   is for when the DNSKEY has been published and we add a safety
   interval before considering the DNSKEY omnipresent.

2. The retire-safety value should only be added to ZSK rollovers if
   there is an actual rollover happening, similar to adding the sign
   delay.

3. The retire-safety value should only be added to KSK rollovers if
   there is an actual rollover happening. We consider the new DS
   omnipresent a bit later, so that we are forced to keep the old DS
   a bit longer.
2025-03-20 10:12:16 +00:00
..
policies Test updating dnssec-policy key lifetime 2024-07-30 10:57:14 +02:00
example.db.in Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00
example2.db.in Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00
example3.db.in Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00
named.conf.in Test updating dnssec-policy key lifetime 2024-07-30 10:57:14 +02:00
named2.conf.in Test updating dnssec-policy key lifetime 2024-07-30 10:57:14 +02:00
setup.sh Fix wrong usage of safety intervals in keymgr 2025-03-20 10:12:16 +00:00
template.db.in Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00