Re: About use bind to do DNSSEC with no correct RSASHA256 signature

2017-09-19 Thread Mark Andrews
Upgrade to 9.10.6, the following should help. 4599. [bug] Fix inconsistencies in inline signing time comparison that were introduced with the introduction of rdatasetheader->resign_lsb. [RT #42112] Really, with any

About use bind to do DNSSEC with no correct RSASHA256 signature

2017-09-18 Thread yaohongyuan
Hi all, We used bind to do the DNSSEC , DYNAMIC ZONES , AND AUTOMATIC SIGNING. But at last week we found that there is just one 'RRSIGNSEC3' record is illegality(No correct RSASHA256 signature) signed by bind. dnssec-verify -o XXX -E pkcs11 XXX.txt.signed Loading zone