> Hmm, thanks for the explanation. However, for this case, while the > activation date was in the near future, the *publish* date was far in > the past.
Apparently it thought this was the first time it was being published, anyway. That information doesn't come from the publication date but from before-and-after comparison of the DNSKEY RRset. If this message came from dnssec-signzone, I guess maybe you were signing the raw zone, rather than re-signing a zone that was already signed? -- Evan Hunt -- e...@isc.org Internet Systems Consortium, Inc. _______________________________________________ Please visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list bind-users mailing list bind-users@lists.isc.org https://lists.isc.org/mailman/listinfo/bind-users