dnssec-signzone retains obsolete signatures

Daniel Stirnimann daniel.stirnimann at switch.ch
Sat Apr 2 14:07:00 UTC 2016


> While this is not a problem for BIND to load the zone it seems
> unexpected to me. Should dnssec-signzone not remove obsolete signatures?

Found out that this issue is fixed in BIND 9.11.0a1:

4305. [bug]    dnssec-signzone was not removing unnecessary rrsigs
               from the zone's apex. [RT #41483]

Specifically, it was fixed on the 28th Jan 2016:
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commit;h=832ab79d1f8bc4edf638780b306888da30ac3a1e

I believe the wording "from the zone's apex" is wrong as it removes
unnecessary rrsigs from the whole zone.

Daniel


More information about the bind-users mailing list