Hi Stefan, we understand your motivation for having two dnssec policies but it would complicate the dnssec code, which already is quite complex, and we don't want to introduce new bugs. I'm sorry. But with manual key management it's possible to sign the zone using more algorithms.
Also as explained before, using more algorithms doesn't result in higher security. Regards, Daniel On 7/23/21 4:13 PM, Schindler, Stefan wrote: > Hi Daniel, > > Would it be possible to activate more than one algorithm in a policy? > > If not, how hard would it be to include that functionality? > Because for some reason a lot of ISP resolvers support RSA only while I would > like to future-proof my zone with ED25519 at the same time. > > Cheers, > Stefan > > > Am Do., 22. Juli 2021 um 19:56 Uhr schrieb Daniel Salzman > <[email protected] <mailto:[email protected]>>: > > Hi Stefan, > > I'm sorry, it's not possible to configure more DNSSEC policies (more > algorithms) per one zone at the same time. > > Maybe, with the manual key management and more configuration files when > generating keys via keymgr, it could work somehow. But I'm not sure and > probably it's not what you are looking for :-) > > Daniel > > On 22. 07. 21 16:55, Schindler, Stefan wrote: > > Hi all > > > > I am currently running these two policies: > > ``` > > policy: > > - id: edecc > > algorithm: ed25519 > > nsec3: on > > - id: rsa > > algorithm: RSASHA256 > > ksk-size: 2048 > > zsk-size: 2048 > > nsec3: on > > ``` > > > > I tried enabling both with this command, but to no effect: > > ``` > > dnssec-policy: [ edecc, rsa ] > > ``` > > > > Is there a way to do both at the same time in one zone? > > > > I am currently running knot 3.0.8 > > > > Cheers, > > Stefan > > > -- https://lists.nic.cz/mailman/listinfo/knot-dns-users
