"Key <foo>: Delaying activation to match the DNSKEY TTL."

Evan Hunt each at isc.org
Thu Jul 7 01:56:57 UTC 2011


> Hmm, thanks for the explanation. However, for this case, while the
> activation date was in the near future, the *publish* date was far in
> the past.

Apparently it thought this was the first time it was being published,
anyway.  That information doesn't come from the publication date but
from before-and-after comparison of the DNSKEY RRset.

If this message came from dnssec-signzone, I guess maybe you were
signing the raw zone, rather than re-signing a zone that was already
signed?

-- 
Evan Hunt -- each at isc.org
Internet Systems Consortium, Inc.



More information about the bind-users mailing list