>> In case the enforcer logged an error it should prepend it with >> 'keystate_ds_x_cmd'. So please grep your logs for that. > > I've something amiss re state mgmt. > > at verbosity = 6, on exec > > /usr/local/opendnssec/sbin/ods-enforcer zone add -z example.info -p lab > > there's no such log entry,
Again, after zone add the DS doesn't get submitted immediately. OpenDNSSEC should first have to make sure the keys and signatures are sufficiently propagated. You'll have to wait for the "waiting for ds-seen" state. > Dec 21 06:11:36 dns ods-enforcerd: INSERT INTO keyState ( > keyDataId, type, state, lastChange, minimize, ttl, rev ) VALUES ( ?, ?, ?, ?, > ?, ?, ? ) > Those "?" don't look promising ... No worries. This is the uncompiled DB query being logged. //Yuri
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Opendnssec-user mailing list Opendnssec-user@lists.opendnssec.org https://lists.opendnssec.org/mailman/listinfo/opendnssec-user