Testing RFC 5011 key roll

2015-04-17 Thread Edward Lewis
I am building named and unbound recursive servers to follow a test of RFC 5011 trust anchor updates, the experiment is documented at http://keyroll.systems. One reason why I'm asking here is in http://jpmens.net/2015/01/21/opendnssec-rfc-5011-bind-and-unbound/ which mentions some issues with RFC 5

Re: Testing RFC 5011 key roll

2015-04-17 Thread Evan Hunt
On Fri, Apr 17, 2015 at 02:46:16PM +, Edward Lewis wrote: > I am building named and unbound recursive servers to follow a test of RFC > 5011 trust anchor updates, the experiment is documented at > http://keyroll.systems. One reason why I'm asking here is in > http://jpmens.net/2015/01/21/opend

Re: Testing RFC 5011 key roll

2015-04-17 Thread Edward Lewis
Thanks. Now have 'ad' bits via both BIND and unbound. Will let you know when I've shot myself in the foot. On 4/17/15, 12:45, "Evan Hunt" wrote: ... >instead of waiting a full 30 days. (This is, I hope obviously, *not* >something you want to run in production. :) ) smime.p7s Description: S