Uploaded image for project: 'OpenDNSSEC'
  1. OpenDNSSEC
  2. OPENDNSSEC-437

Signature problem on SOA RRset

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 1.4.1
    • Fix Version/s: 1.4.13, 2.1.0
    • Component/s: Signer
    • Labels:
      None
    • Sprint:
      1.4.2, 1.4.7rc1

      Description

      Mathieu Arnold reported:

      Yesterday, my monitoring reported a lot of faulty zones, validns complained
      of :

      1. validns -p all -z 1-wire.fr master/1-wire.fr.signed
        master/1-wire.fr.signed:15: 1-wire.fr. RRSIG(SOA): cannot verify the
        signature

      And some more info:

      • What RRtypes where bogus? Only SOA or also other RRtypes?

      Only the SOA is.

      • If only SOA, what are your SOA parameters (from kasp.xml)?

      <SOA>
      <TTL>PT12H</TTL>
      <Minimum>PT10M</Minimum>
      <Serial>counter</Serial>
      </SOA>

      • What HSM are you using?

      SoftHSM.

      • Was there anything special going on (ods-signer commands, change in
      signconf parameters, ...)

      There might have been a ZSK rollover before that.

      I suspect a corner case condition where either:

      • the signature for the updated soa record was not renewed, or
      • the signature was renewed before updating the soa record

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              hodar Hoda Rohani
              Reporter:
              matthijs Matthijs Mekking
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 4 days
                  4d
                  Remaining:
                  Remaining Estimate - 4 days
                  4d
                  Logged:
                  Time Spent - Not Specified
                  Not Specified