Re: Still seeing some ALG-7 DNSSE

2021-04-12 Thread @lbutlr
> On 12 Apr 2021, at 01:12, Matthijs Mekking wrote: > > > > On 11-04-2021 01:22, @lbutlr wrote: >> On 06 Apr 2021, at 01:13, Matthijs Mekking wrote: >>> In 9.16.13, a new "dnssec-policy" option is introduced, "purge-keys". By >>> default the keys are retained for 90 days after their latest

Re: Still seeing some ALG-7 DNSSE

2021-04-12 Thread Matthijs Mekking
On 11-04-2021 01:22, @lbutlr wrote: On 06 Apr 2021, at 01:13, Matthijs Mekking wrote: In 9.16.13, a new "dnssec-policy" option is introduced, "purge-keys". By default the keys are retained for 90 days after their latest usage. So in that case keys will be cleaned up automatically. Excell

Re: Still seeing some ALG-7 DNSSE

2021-04-10 Thread @lbutlr
On 06 Apr 2021, at 01:13, Matthijs Mekking wrote: > In 9.16.13, a new "dnssec-policy" option is introduced, "purge-keys". By > default the keys are retained for 90 days after their latest usage. So in > that case keys will be cleaned up automatically. Excellent. Does that go in the zone record

Re: Still seeing some ALG-7 DNSSE

2021-04-06 Thread Matthijs Mekking
Most likely you have to delete those files manually. In 9.16.13, a new "dnssec-policy" option is introduced, "purge-keys". By default the keys are retained for 90 days after their latest usage. So in that case keys will be cleaned up automatically. If you run a lower version, or if you set "p

Still seeing some ALG-7 DNSSE

2021-04-05 Thread @lbutlr
If I do: cd /etc/named/working/main/ for i in *; do dig $i +dnssec | grep "A 13 2" | awk '{print $1}';done I see a list of all the domains on the system, so that's good, everything has a ALG-13 signature. If I do for i in *; do dig $i +dnssec | grep "A 7 2" | awk '{print $1}';done I see a lis