mirror of
https://github.com/isc-projects/bind9.git
synced 2026-03-12 21:52:47 -04:00
When named starts it creates an empty KEYDATA record in the managed-keys zone as a placeholder, then schedules a key refresh. If key refresh fails for some reason (e.g. connectivity problems), named will load the placeholder key into secroots as a trusted key during the next startup, which will break the chain of trust, and named will never recover from that state until managed-keys.bind and managed-keys.bind.jnl files are manually deleted before (re)starting named again. Before calling load_secroots(), check that we are not dealing with a placeholder. |
||
|---|---|---|
| .. | ||
| bind9 | ||
| dns | ||
| irs | ||
| isc | ||
| isccc | ||
| isccfg | ||
| ns | ||
| .gitignore | ||
| Makefile.am | ||