Re: DNSSEC signing issues

2011-04-22 Thread Mark Andrews

In message 8D870AB38C30EC4C848A11A3F83D20D801733325E60C@exchange2007.mmicmanho
menet.local, Security Admin (NetSec) writes:
 
 I am running BIND 9.4.2-P2 on OpenBSD v4.8
 
 I have created the ZSK and KSK and added the keys to my zonefile mydomain.=
 hosts  using the cat command to append to the end of the host file.
 
 When attempting to use the following command dnssec-signzone -N INCREMENT =
 mydomain.hosts I get the following error:
 
 dnssec-signzone: error: dns_master_load: mydomain.hosts:15: mydomain.com: n=
 ot at top of zone
 dnssec-signzone: failed loading zone from ' mydomain.hosts': not at top of =
 zone
 
 I own this domain and the DNS servers associated with them.  Line 15 refere=
 nced in the above error is an MX record within the host file. I am unsure h=
 ow to debug this error.  Any help would be appreciated.

Specify the zone name with -o mydomain.com.  By default the zone matches
the file name.
 
 --_000_8D870AB38C30EC4C848A11A3F83D20D801733325E60Cexchange200_
 Content-Type: text/html; charset=us-ascii
 Content-Transfer-Encoding: quoted-printable
 
 html xmlns:v=3Durn:schemas-microsoft-com:vml xmlns:o=3Durn:schemas-micr=
 osoft-com:office:office xmlns:w=3Durn:schemas-microsoft-com:office:word =
 xmlns:m=3Dhttp://schemas.microsoft.com/office/2004/12/omml; xmlns=3Dhttp:=
 //www.w3.org/TR/REC-html40headmeta http-equiv=3DContent-Type content=
 =3Dtext/html; charset=3Dus-asciimeta name=3DGenerator content=3DMicros=
 oft Word 14 (filtered medium)style!--
 /* Font Definitions */
 @font-face
   {font-family:Cambria Math;
   panose-1:2 4 5 3 5 4 6 3 2 4;}
 @font-face
   {font-family:Calibri;
   panose-1:2 15 5 2 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
   {margin:0in;
   margin-bottom:.0001pt;
   font-size:11.0pt;
   font-family:Calibri,sans-serif;}
 a:link, span.MsoHyperlink
   {mso-style-priority:99;
   color:blue;
   text-decoration:underline;}
 a:visited, span.MsoHyperlinkFollowed
   {mso-style-priority:99;
   color:purple;
   text-decoration:underline;}
 span.EmailStyle17
   {mso-style-type:personal-compose;
   font-family:Calibri,sans-serif;
   color:windowtext;}
 .MsoChpDefault
   {mso-style-type:export-only;
   font-family:Calibri,sans-serif;}
 @page WordSection1
   {size:8.5in 11.0in;
   margin:1.0in 1.0in 1.0in 1.0in;}
 div.WordSection1
   {page:WordSection1;}
 --/style!--[if gte mso 9]xml
 o:shapedefaults v:ext=3Dedit spidmax=3D1026 /
 /xml![endif]--!--[if gte mso 9]xml
 o:shapelayout v:ext=3Dedit
 o:idmap v:ext=3Dedit data=3D1 /
 /o:shapelayout/xml![endif]--/headbody lang=3DEN-US link=3Dblue vli=
 nk=3Dpurplediv class=3DWordSection1p class=3DMsoNormalI am running BIN=
 D 9.4.2-P2 on OpenBSD v4.8o:p/o:p/pp class=3DMsoNormalo:pnbsp;/=
 o:p/pp class=3DMsoNormalI have created the ZSK and KSK and added the k=
 eys to my zonefile #8220;mydomain.hosts#8221;nbsp; using the #8220;cat=
 #8221; command to append to the end of the host file.o:p/o:p/pp clas=
 s=3DMsoNormalo:pnbsp;/o:p/pp class=3DMsoNormalWhen attempting to =
 use the following command #8220;dnssec-signzone -N INCREMENT mydomain.host=
 s#8221; I get the following error:o:p/o:p/pp class=3DMsoNormalo:p=
 nbsp;/o:p/pp class=3DMsoNormalidnssec-signzone: error: dns_master=
 _load: mydomain.hosts:15: mydomain.com: not at top of zoneo:p/o:p/i/=
 pp class=3DMsoNormalidnssec-signzone: failed loading zone from ' mydom=
 ain.hosts': not at top of zoneo:p/o:p/i/pp class=3DMsoNormalio=
 :pnbsp;/o:p/i/pp class=3DMsoNormalI own this domain and the DNS s=
 ervers associated with them.nbsp; Line 15 referenced in the above error is=
  an MX record within the host file. I am unsure how to debug this error.nb=
 sp; Any help would be appreciated.o:p/o:p/p/div/body/html=
 
 --_000_8D870AB38C30EC4C848A11A3F83D20D801733325E60Cexchange200_--
 
 --===5749675706925016482==
 Content-Type: text/plain; charset=us-ascii
 MIME-Version: 1.0
 Content-Transfer-Encoding: 7bit
 Content-Disposition: inline
 
 ___
 bind-users mailing list
 bind-users@lists.isc.org
 https://lists.isc.org/mailman/listinfo/bind-users
 --===5749675706925016482==--
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


Re: DNSSEC signing issues

2011-04-22 Thread fakessh
Le vendredi 22 avril 2011 04:20, Security Admin (NetSec) a écrit :
 I am running BIND 9.4.2-P2 on OpenBSD v4.8

 I have created the ZSK and KSK and added the keys to my zonefile
 mydomain.hosts  using the cat command to append to the end of the host
 file.

 When attempting to use the following command dnssec-signzone -N INCREMENT
 mydomain.hosts I get the following error:

 dnssec-signzone: error: dns_master_load: mydomain.hosts:15: mydomain.com:
 not at top of zone dnssec-signzone: failed loading zone from '
 mydomain.hosts': not at top of zone

 I own this domain and the DNS servers associated with them.  Line 15
 referenced in the above error is an MX record within the host file. I am
 unsure how to debug this error.  Any help would be appreciated.

we sign areas as explained in the page of the isc we take 1 of 2 record DNSKEY 
we publish in the isc after you retrieve the record is dlv TXT resigns areas 
and wait for the secondaries restet


-- 
 http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0x092164A7
 gpg --keyserver pgp.mit.edu --recv-key 092164A7


pgpheC9C4tItj.pgp
Description: PGP signature
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

DNSSEC signing issues

2011-04-21 Thread Security Admin (NetSec)
I am running BIND 9.4.2-P2 on OpenBSD v4.8

I have created the ZSK and KSK and added the keys to my zonefile 
mydomain.hosts  using the cat command to append to the end of the host file.

When attempting to use the following command dnssec-signzone -N INCREMENT 
mydomain.hosts I get the following error:

dnssec-signzone: error: dns_master_load: mydomain.hosts:15: mydomain.com: not 
at top of zone
dnssec-signzone: failed loading zone from ' mydomain.hosts': not at top of zone

I own this domain and the DNS servers associated with them.  Line 15 referenced 
in the above error is an MX record within the host file. I am unsure how to 
debug this error.  Any help would be appreciated.
___
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users