mirror of
https://github.com/isc-projects/bind9.git
synced 2026-04-29 01:49:02 -04:00
3528. [func] New "dnssec-coverage" command scans the timing metadata for a set of DNSSEC keys and reports if a lapse in signing coverage has been scheduled inadvertently. (Note: This tool depends on python; it will not be built or installed on systems that do not have a python interpreter.) [RT #28098]
12 lines
462 B
Text
12 lines
462 B
Text
This set includes one KSK rollover. The first KSK is deleted
|
|
and its successor published prior to the first KSK being deactivated
|
|
and its successor activated. Tool output should resemble:
|
|
|
|
Checking KSK events for zone example.com, algorithm 7:
|
|
ERROR: After 2012-05-Dec (21:22:19):
|
|
Delete: example.com/007/06219 (KSK)
|
|
Publish: example.com/007/20559 (KSK)
|
|
No KSK's are both active and published
|
|
|
|
Checking ZSK events for zone example.com, algorithm 7:
|
|
OK
|