Aha!

> I've imported keys into OpenDNSSEC that used to be rolled by ZSK.

I meant ZKT.

> It took a few attempts, but after manually cleaning the DB from
> the zone, keys and key references, the import went through fine.
> 
> Now the signer is stuck in "I will [read] zone xyz" without any
> problem that I could find with reading it:

There is a problem nonetheless, and it is specific to the ZKT origin.

The statement "$INCLUDE dnskey.db" that includes another file into
which ZKT stores DNSKEY records had to be removed.  After that it
all went through fine.

Well... I suppose this is now documented, so it is not so bad ;-)

-Rick
_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to