On 10/29/19 3:49 PM, Casper Gielen wrote: > I want to get a specific key from OpenDNSSEC but this seems impossible > with version 2.1.3 (from the Debian repositories).
Not sure what you mean with "get a key" List key active, export secret/public key, or get the information usable for DS records? > ods-enforcer key export used to list the keytag but it no longer does. > Now it has become impossible to identify the keys other than calculating > the keytag yourself. There are no changes in this respect in the 2.1 branch. I won't do structural changes to maintenance branches. Computing keytags should never be necessary, that would indeed need fixing. The command ods-enforcer key export is primary used to export either DNSKEY records or DS records suitable to submit to the parent zone. In which case you'd almost always want to submit everything. The command "ods-enforcer key list" will list keys for other purposes. With the additional "-v" flag it will also output the keytags for each key. I would agree that "key export" and "key list" are confusing in their usage, but overhoaling the CLI isn't worked on yet and is a very structural change. > PS. Is OpenDNSSEC doing alright? Things have been very quiet on the > mailing lists and there seems to be hardly any development going on. Just a release out the door, and commits in both main tree as on user repos. \Berry
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
