Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Daniel Ryslink
Hello, I have the following zone definition included into named.conf: zone example.com in { type master; file master/example.com; update-policy local; auto-dnssec maintain; key-directory /etc/namedb/keys/; masterfile-format text; inline-signing yes; }; Keys are ready in /etc/namedb/keys/,

Re: Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Mark Andrews
In message 5333fe7a.8030...@dialtelecom.cz, Daniel Ryslink writes: Hello, I have the following zone definition included into named.conf: zone example.com in { type master; file master/example.com; update-policy local; auto-dnssec maintain; key-directory /etc/namedb/keys/;

Re: Problems with auto-dnssec maintain on BIND 9.9.5 (latest patch, FreeBSD)

2014-03-27 Thread Tony Finch
Daniel Ryslink daniel.rysl...@dialtelecom.cz wrote: At first, when the zone was not signed at all, all that sufficed was to do rndc loadkeys example.com, and when I later used rndc signing -list example.com, the keys set via dnssec-settime as active in the keys directory were displayed. Note