> But then, once the lifetime of a KSK has expired, the > > KSK Retirement reached > > message should be logged. > Did I understand that wrong ? If yes, what is the exact trigger for the > "KSK Retirement reached" message then ?
I can't find such a message (in the 1.4) source. However this should be
logged as soon as the ksk gets to the ready state:
"WARNING: New KSK has reached the ready state; please submit the DS for
%s and use ods-ksmutil key ds-seen when the DS appears in the DNS.",
//Yuri
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
