On Mon, 9 Mar 2020, Berry A.W. van Halderen via Opendnssec-user wrote:
I have a question to those of you who are using OpenDNSSEC for signing your registry zones. At Norid, we are currently in the process of testing OpenDNSSEC version 2 with a plan to migrate when we feel comfortable with that.
The fedora packages of opendnssec-2.x contain hooks to automatically migrate 1.x to 2.x. This has only been tested to work with freeipa, which uses relatively small zones and we wouldn't really catch double signing bugs or anything as long as DNSSEC validation keeps working. I did have to make small changes to the upstream migration scripts. One part was storing in the db that migration has already happened. Perhaps upstream can grab those downstream changes for their next release too :) Paul _______________________________________________ Opendnssec-user mailing list [email protected] https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
