>> Does anyone have an idea what more needs to be done to zero in on >> this problem? > > Hmm. My first guess would be that it involves a resalt. Your log lines > seem to indicate that no new NSECS are being generated. Yet a resign > solves the problem. Could you compare the NSEC3PARAM from the failing > zone to the one after the manual resign?
It seems this was a correct hunch, ref. my other posting. Regards, - HÃ¥vard _______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
