-
Type:
Bug
-
Status: Accepted
-
Resolution: Fixed
-
Affects Version/s: None
-
Fix Version/s: 88 : 13 Feb
-
Labels:
The Enforcer makes the next KSK active (used for signing) when initiating a KSK rollover. But the key is not considered to be in the state ACTIVE until the DS has been seen.
The Auditor does however start to count the time in use when the rollover is initiated. This means that you will always get the warning at the end of the lifetime for the KSK. Because the Enforcer starts the lifetime when the key reaches the state ACTIVE.
Is this a problem? Or is it a good warning that the key now have actually created signatures longer than expected?