Aha! > I've imported keys into OpenDNSSEC that used to be rolled by ZSK.
I meant ZKT. > It took a few attempts, but after manually cleaning the DB from > the zone, keys and key references, the import went through fine. > > Now the signer is stuck in "I will [read] zone xyz" without any > problem that I could find with reading it: There is a problem nonetheless, and it is specific to the ZKT origin. The statement "$INCLUDE dnskey.db" that includes another file into which ZKT stores DNSKEY records had to be removed. After that it all went through fine. Well... I suppose this is now documented, so it is not so bad ;-) -Rick _______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
