Re: [Pdns-users] Slaves do not return RRSIGs when DO flag is set

2014-08-08 Thread Posner, Sebastian
Julian K. wrote: > > There's your problem: not presigned. You need to set them > > "presigned" > > so that pdns knows they're signed and that it needs to send rrsig > > records. To do this, you'll need to run > > > > pdnssec set-presigned zone > I want the bindbackend to manage the keys an

Re: [Pdns-users] Slaves do not return RRSIGs when DO flag is set

2014-08-07 Thread Julian K.
There’s your problem: not presigned. You need to set them “presigned” so that pdns knows they’re signed and that it needs to send rrsig records. To do this, you’ll need to run pdnssec set-presigned zone I want the bindbackend to manage the keys and transparently sign my zones. Does this r

Re: [Pdns-users] Slaves do not return RRSIGs when DO flag is set

2014-08-05 Thread Leon Weber
On 05.08.2014 17:52:05, Julian K. wrote: > Aug 5 17:11:08 h1988784 pdns[12055]: Domain 'ssl-tools.net' is > fresh (not presigned, no RRSIG check) There’s your problem: not presigned. You need to set them “presigned” so that pdns knows they’re signed and that it needs to send rrsig records. To d

[Pdns-users] Slaves do not return RRSIGs when DO flag is set

2014-08-05 Thread Julian K.
Dead pdns users, I am running a powerdns master with bind backend and a bind-dnssec-db. Two superslaves receive their zones from the master using zone transfer. After securing a zone and incrementing the serial, the master returns RRSIG records if the DO flag is set, but the slaves do not: |`