> I guess you mean "key generate --interval" instead of "key generate --period" 
> ?

indeed.

>> Long term workaround:
>> Use a different key length for ZSK than KSK.
> 
> We already do. KSK length is 2048, ZSK 1024.

Then you have a different problem. Please check which user OpenDNSSEC
runs as and make sure that your HSM allows that user write access.

//Yuri

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to