-
Type: Improvement
-
Status: Open
-
Priority: Minor
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: future
-
Component/s: None
-
Labels:None
Feature proposal:
Bootstrap ODS with tuple (kasp.xml, HSM, signed zonefile).
That is without the enforcer state database. This could be used for:
- recovery when database corrupt,
- migration between ODS versions or other signing software,
Migration this way is more future proof than exporting databases. Zonefiles are very well defined.
Hurdles:
- Enforcer needs to parse zonefile
- Match DNSKEYS to HSM keys
- When in rollover figure out towards which key
- Assume everything rumoured, wait extra safety margin (i.e. a TTL)
- Ask user for state of DS