Re: After switching to "dnssec-policy", existing RRs are still signed with the "old" ZSK

2022-05-11 Thread Tom
On 11.05.22 11:26, Mark Andrews wrote: Signature-refresh determines when the RRSIGs will be replaced by looking at the expiration time and working backwards. New RRSIGs are generate Using signature-interval. Ah, perfect. Thx. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to

Re: After switching to "dnssec-policy", existing RRs are still signed with the "old" ZSK

2022-05-11 Thread Mark Andrews
Signature-refresh determines when the RRSIGs will be replaced by looking at the expiration time and working backwards. New RRSIGs are generate Using signature-interval. -- Mark Andrews > On 11 May 2022, at 18:15, Tom wrote: > > Hi list > > After switching from "semi-automatic"-signing to