> I guess you mean "key generate --interval" instead of "key generate --period" > ?
indeed. >> Long term workaround: >> Use a different key length for ZSK than KSK. > > We already do. KSK length is 2048, ZSK 1024. Then you have a different problem. Please check which user OpenDNSSEC runs as and make sure that your HSM allows that user write access. //Yuri
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
