dnssec-keyfromlabel out of memory

Mark Andrews marka at isc.org
Wed Jul 22 00:02:35 UTC 2009


Mark Andrews writes:
> 
> In message <1E4636828B4AD841900A31378A9FE3CD02CA149BC5 at usemp11.ins.com>, Greg
> .R
> abil at ins.com writes:
> > Hello,
> > Trying to run 'dnssec-keyfromlabel' from 9.6.1 distro on RHEL5.
> > 
> > Configured with:
> > ./configure --with-openssl=3D/usr/local/ssl --with-pkcs11 --enable-threads 
> =
> > --enable-ipv6 --enable-static
> > 
> > Using PKCS11 engine from OpenSolaris patch for OpenSSL 0.9.8k.
> > 
> > Here's my test:
> > 
> > /opt/dnssec/bind-9.6.1/bin/dnssec/dnssec-keyfromlabel -a RSASHA1 -l foobar 
> =
> > foobar
> > dnssec-keyfromlabel: failed to generate key foobar/RSASHA1: out of memory
> 
> dnssec-keyfromlabel -a RSASHA1 -l pkcs11:foobar foobar

This assumes you have already created a RSA key called "foobar" in the HSM.

> > I have 1GB of memory on this box.  Is this error legitimate?  If so, how mu
> =
> > ch memory is expected to be needed for this?  If not, any ideas what the pr
> =
> > oblem may be?
> > 
> > Thanks,
> > Greg
> > 
> > 
> > A. Gregory Rabil | Lead Software Architect | BT Diamond IP |
> > Tel: +1 (610) 423-4770 | Fax: +1 (610) 423-4774 | Greg.Rabil at bt.com<mailto:
> =
> > Greg.Rabil at bt.com> |  http://bt.diamondip.com
> -- 
> Mark Andrews, ISC
> 1 Seymour St., Dundas Valley, NSW 2117, Australia
> PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org



More information about the bind-users mailing list