1*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.018: debug: Check RFC5011 status 2*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.018: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 3*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.018: debug: Check KSK status 4*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.018: debug: No active KSK found: generate new one 5*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.330: info: "dyn.example.net.": generated new KSK 52935 6*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.330: debug: Check ZSK status 7*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.330: debug: No active ZSK found: generate new one 8*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: info: "dyn.example.net.": generated new ZSK 30323 9*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: debug: Re-signing necessary: Modfied zone key set 10*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: notice: "dyn.example.net.": re-signing triggered: Modfied zone key set 11*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: debug: Writing key file "./dyn.example.net/dnskey.db" 12*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: debug: Signing zone "dyn.example.net." 13*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: notice: "dyn.example.net.": freeze dynamic zone 14*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: debug: freeze dynamic zone "dyn.example.net." 15*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.368: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 16*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.374: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 17*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.374: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 18*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.382: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: Zone contains NSEC records. Use -u to update to NSEC3." 19*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.382: error: "dyn.example.net.": signing failed! 20*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.382: notice: "dyn.example.net.": thaw dynamic zone 21*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.382: debug: thaw dynamic zone "dyn.example.net." 22*00b67f09SDavid van Moolenbroek2010-02-21 19:43:15.382: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 23*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.415: debug: Check RFC5011 status 24*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.416: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 25*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.416: debug: Check KSK status 26*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.416: debug: Check ZSK status 27*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.416: debug: Re-signing not necessary! 28*00b67f09SDavid van Moolenbroek2010-02-21 19:45:36.416: debug: Check if there is a parent file to copy 29*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Check RFC5011 status 30*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 31*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Check KSK status 32*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Check ZSK status 33*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Re-signing necessary: Option -f 34*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: notice: "dyn.example.net.": re-signing triggered: Option -f 35*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Writing key file "./dyn.example.net/dnskey.db" 36*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Signing zone "dyn.example.net." 37*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: notice: "dyn.example.net.": freeze dynamic zone 38*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: freeze dynamic zone "dyn.example.net." 39*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.448: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 40*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.457: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 41*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.458: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 42*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.473: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 generation requested with NSEC only DNSKEY" 43*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.473: error: "dyn.example.net.": signing failed! 44*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.473: notice: "dyn.example.net.": thaw dynamic zone 45*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.473: debug: thaw dynamic zone "dyn.example.net." 46*00b67f09SDavid van Moolenbroek2010-02-21 19:45:41.473: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 47*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: Check RFC5011 status 48*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 49*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: Check KSK status 50*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: Check ZSK status 51*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: Re-signing necessary: Option -f 52*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: notice: "dyn.example.net.": re-signing triggered: Option -f 53*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.899: debug: Writing key file "./dyn.example.net/dnskey.db" 54*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.900: debug: Signing zone "dyn.example.net." 55*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.900: notice: "dyn.example.net.": freeze dynamic zone 56*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.900: debug: freeze dynamic zone "dyn.example.net." 57*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.900: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 58*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.910: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 59*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.910: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 60*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.926: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 iterations too big for weakest DNSKEY strength. Maximum iterations allowed 0." 61*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.926: error: "dyn.example.net.": signing failed! 62*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.926: notice: "dyn.example.net.": thaw dynamic zone 63*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.926: debug: thaw dynamic zone "dyn.example.net." 64*00b67f09SDavid van Moolenbroek2010-02-21 19:47:06.926: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 65*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.972: debug: Check RFC5011 status 66*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.972: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 67*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.972: debug: Check KSK status 68*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.972: debug: Check ZSK status 69*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: debug: Re-signing necessary: Option -f 70*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: notice: "dyn.example.net.": re-signing triggered: Option -f 71*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: debug: Writing key file "./dyn.example.net/dnskey.db" 72*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: debug: Signing zone "dyn.example.net." 73*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: notice: "dyn.example.net.": freeze dynamic zone 74*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: debug: freeze dynamic zone "dyn.example.net." 75*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.973: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 76*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.982: debug: Dynamic Zone signing: zone file manually edited: Use it as new input file 77*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.982: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 78*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.983: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 79*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.999: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 iterations too big for weakest DNSKEY strength. Maximum iterations allowed 0." 80*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.999: error: "dyn.example.net.": signing failed! 81*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.999: notice: "dyn.example.net.": thaw dynamic zone 82*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.999: debug: thaw dynamic zone "dyn.example.net." 83*00b67f09SDavid van Moolenbroek2010-02-21 19:58:40.999: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 84*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: Check RFC5011 status 85*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 86*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: Check KSK status 87*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: Check ZSK status 88*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: Re-signing necessary: Option -f 89*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: notice: "dyn.example.net.": re-signing triggered: Option -f 90*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.833: debug: Writing key file "./dyn.example.net/dnskey.db" 91*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.834: debug: Signing zone "dyn.example.net." 92*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.834: notice: "dyn.example.net.": freeze dynamic zone 93*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.834: debug: freeze dynamic zone "dyn.example.net." 94*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.834: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 95*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.844: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 96*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.844: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 97*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.878: debug: Cmd dnssec-signzone return: "zone.db.dsigned" 98*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.878: notice: "dyn.example.net.": thaw dynamic zone 99*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.878: debug: thaw dynamic zone "dyn.example.net." 100*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.878: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 101*00b67f09SDavid van Moolenbroek2010-02-21 20:00:48.884: debug: Signing completed after 0s. 102*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.175: debug: Check RFC5011 status 103*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.175: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 104*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.175: debug: Check KSK status 105*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.175: debug: Check ZSK status 106*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: debug: Re-signing necessary: Option -f 107*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: notice: "dyn.example.net.": re-signing triggered: Option -f 108*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: debug: Writing key file "./dyn.example.net/dnskey.db" 109*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: debug: Signing zone "dyn.example.net." 110*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: notice: "dyn.example.net.": freeze dynamic zone 111*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: debug: freeze dynamic zone "dyn.example.net." 112*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.176: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 113*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.181: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 114*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.181: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 115*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.202: debug: Cmd dnssec-signzone return: "zone.db.dsigned" 116*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.202: notice: "dyn.example.net.": thaw dynamic zone 117*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.203: debug: thaw dynamic zone "dyn.example.net." 118*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.203: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 119*00b67f09SDavid van Moolenbroek2010-02-21 20:01:11.208: debug: Signing completed after 0s. 120*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.175: debug: Check RFC5011 status 121*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.175: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 122*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.175: debug: Check KSK status 123*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.175: debug: Check ZSK status 124*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.176: debug: Re-signing not necessary! 125*00b67f09SDavid van Moolenbroek2010-02-21 20:01:17.176: debug: Check if there is a parent file to copy 126*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: Check RFC5011 status 127*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 128*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: Check KSK status 129*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: Check ZSK status 130*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: Re-signing necessary: re-signing interval (2d) reached 131*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: notice: "dyn.example.net.": re-signing triggered: re-signing interval (2d) reached 132*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.326: debug: Writing key file "./dyn.example.net/dnskey.db" 133*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.327: debug: Signing zone "dyn.example.net." 134*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.327: notice: "dyn.example.net.": freeze dynamic zone 135*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.327: debug: freeze dynamic zone "dyn.example.net." 136*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.327: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 137*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.388: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 138*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.425: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 139*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.471: debug: Cmd dnssec-signzone return: "zone.db.dsigned" 140*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.471: notice: "dyn.example.net.": thaw dynamic zone 141*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.471: debug: thaw dynamic zone "dyn.example.net." 142*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.471: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 143*00b67f09SDavid van Moolenbroek2010-02-25 23:42:29.486: debug: Signing completed after 0s. 144*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Check RFC5011 status 145*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 146*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Check KSK status 147*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Check ZSK status 148*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Re-signing necessary: re-signing interval (2d) reached 149*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: notice: "dyn.example.net.": re-signing triggered: re-signing interval (2d) reached 150*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Writing key file "./dyn.example.net/dnskey.db" 151*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Signing zone "dyn.example.net." 152*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: notice: "dyn.example.net.": freeze dynamic zone 153*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: freeze dynamic zone "dyn.example.net." 154*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.770: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net." 155*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.852: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db 156*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.875: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private 2>&1" 157*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.950: debug: Cmd dnssec-signzone return: "zone.db.dsigned" 158*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.950: notice: "dyn.example.net.": thaw dynamic zone 159*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.950: debug: thaw dynamic zone "dyn.example.net." 160*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.950: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net." 161*00b67f09SDavid van Moolenbroek2010-03-02 10:59:46.964: debug: Signing completed after 0s. 162