>> Does anyone have an idea what more needs to be done to zero in on
>> this problem?
>
> Hmm. My first guess would be that it involves a resalt. Your log lines
> seem to indicate that no new NSECS are being generated. Yet a resign
> solves the problem. Could you compare the NSEC3PARAM from the failing
> zone to the one after the manual resign?

It seems this was a correct hunch, ref. my other posting. 

Regards,

- HÃ¥vard
_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to