-
Type:
Bug
-
Status: Accepted
-
Resolution: Fixed
-
Affects Version/s: None
-
Fix Version/s: 107 : 27 Jun
-
Labels:
The TTL of the DNSKEY RRset is not updated in the signed zone
Start signing your zone.
Change the DNSKEY TTL in signconf.
sudo ods-signer update se
Check syslog that it has this new value.
Jun 26 06:27:57 fou ods-signerd: [signconf] zone se signconf: RESIGN[PT300S] REFRESH[PT600S] VALIDITY[PT1800S] DENIAL[PT1800S] JITTER[PT300S] OFFSET[PT300S] NSEC[47] DNSKEYTTL[PT3600S] SOATTL[PT60S] MINIMUM[PT60S] SERIAL[unixtime] AUDIT[0]
But the signed zone will not get this value.