"Key <foo>: Delaying activation to match the DNSKEY TTL."
Evan Hunt
each at isc.org
Thu Jul 7 01:56:57 UTC 2011
> Hmm, thanks for the explanation. However, for this case, while the
> activation date was in the near future, the *publish* date was far in
> the past.
Apparently it thought this was the first time it was being published,
anyway. That information doesn't come from the publication date but
from before-and-after comparison of the DNSKEY RRset.
If this message came from dnssec-signzone, I guess maybe you were
signing the raw zone, rather than re-signing a zone that was already
signed?
--
Evan Hunt -- each at isc.org
Internet Systems Consortium, Inc.
More information about the bind-users
mailing list