1*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: Check RFC5011 status 2*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 3*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: Check KSK status 4*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: Check ZSK status 5*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: Re-signing not necessary! 6*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: Check if there is a parent file to copy 7*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: Check RFC5011 status 8*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 9*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: Check KSK status 10*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: Check ZSK status 11*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: Re-signing not necessary! 12*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: Check if there is a parent file to copy 13*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: Check RFC5011 status 14*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 15*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: Check KSK status 16*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: Check ZSK status 17*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: Re-signing not necessary! 18*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: Check if there is a parent file to copy 19*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: Check RFC5011 status 20*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 21*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: Check KSK status 22*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: Check ZSK status 23*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: Re-signing not necessary! 24*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: Check if there is a parent file to copy 25*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: Check RFC5011 status 26*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 27*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: Check KSK status 28*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: Check ZSK status 29*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: Re-signing not necessary! 30*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: Check if there is a parent file to copy 31*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: Check RFC5011 status 32*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 33*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: Check KSK status 34*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: Check ZSK status 35*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: Re-signing not necessary! 36*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: Check if there is a parent file to copy 37*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.019: debug: Check RFC5011 status 38*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.019: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 39*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Check KSK status 40*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Check ZSK status 41*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Re-signing necessary: Option -f 42*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: notice: "example.net.": re-signing triggered: Option -f 43*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Writing key file "./example.net/dnskey.db" 44*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Incrementing serial number in file "./example.net/zone.db" 45*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: Signing zone "example.net." 46*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.021: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 47*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: Cmd dnssec-signzone return: "zone.db.signed" 48*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: Signing completed after 0s. 49*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: notice: "example.net.": distribution triggered 50*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: Distribute zone "example.net." 51*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed " 52*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./" 53*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: notice: "example.net.": reload triggered 54*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: Reload zone "example.net." 55*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed " 56*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.139: debug: ./dist.sh reload return: "rndc reload example.net. " 57*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: Check RFC5011 status 58*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 59*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: Check KSK status 60*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: Check ZSK status 61*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: Re-signing not necessary! 62*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.671: debug: Check if there is a parent file to copy 63*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: Check RFC5011 status 64*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 65*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: Check KSK status 66*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: Check ZSK status 67*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: Re-signing necessary: Option -f 68*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: notice: "example.net.": re-signing triggered: Option -f 69*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: Writing key file "./example.net/dnskey.db" 70*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: Incrementing serial number in file "./example.net/zone.db" 71*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: Signing zone "example.net." 72*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 73*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: Cmd dnssec-signzone return: "zone.db.signed" 74*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: Signing completed after 0s. 75*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: notice: "example.net.": distribution triggered 76*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: Distribute zone "example.net." 77*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed " 78*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./" 79*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: notice: "example.net.": reload triggered 80*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: Reload zone "example.net." 81*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed " 82*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.797: debug: ./dist.sh reload return: "rndc reload example.net. " 83*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: Check RFC5011 status 84*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 85*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: Check KSK status 86*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: Check ZSK status 87*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: Lifetime(1209600 +/-150 sec) of active key 33002 exceeded (2394625 sec) 88*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: ->depreciate it 89*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: ->activate published key 29240 90*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: notice: "example.net.": lifetime of zone signing key 33002 exceeded: ZSK rollover done 91*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: New key for publishing needed 92*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: ->creating new key 5525 93*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: info: "example.net.": new key 5525 generated for publishing 94*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: Re-signing necessary: Modfied zone key set 95*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: notice: "example.net.": re-signing triggered: Modfied zone key set 96*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: Writing key file "./example.net/dnskey.db" 97*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: Incrementing serial number in file "./example.net/zone.db" 98*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: Signing zone "example.net." 99*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 100*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.733: debug: Cmd dnssec-signzone return: "zone.db.signed" 101*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.733: debug: Signing completed after 0s. 102*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: Check RFC5011 status 103*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 104*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: Check KSK status 105*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: Check ZSK status 106*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: Re-signing not necessary! 107*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: Check if there is a parent file to copy 108*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: Check RFC5011 status 109*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 110*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: Check KSK status 111*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: Check ZSK status 112*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: Re-signing not necessary! 113*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: Check if there is a parent file to copy 114*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: Check RFC5011 status 115*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 116*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: Check KSK status 117*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: Check ZSK status 118*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: Re-signing not necessary! 119*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: Check if there is a parent file to copy 120*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: Check RFC5011 status 121*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 122*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: Check KSK status 123*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: Check ZSK status 124*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: Re-signing not necessary! 125*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: Check if there is a parent file to copy 126*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Check RFC5011 status 127*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 128*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Check KSK status 129*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Check ZSK status 130*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Re-signing necessary: Option -f 131*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: notice: "example.net.": re-signing triggered: Option -f 132*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Writing key file "./example.net/dnskey.db" 133*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Incrementing serial number in file "./example.net/zone.db" 134*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Signing zone "example.net." 135*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 136*00b67f09SDavid van Moolenbroek2010-02-21 19:32:16.019: debug: Cmd dnssec-signzone return: "zone.db.signed" 137*00b67f09SDavid van Moolenbroek2010-02-21 19:32:16.019: debug: Signing completed after 1s. 138*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.232: debug: Check RFC5011 status 139*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.232: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 140*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Check KSK status 141*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Check ZSK status 142*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Re-signing necessary: Option -f 143*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: notice: "example.net.": re-signing triggered: Option -f 144*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Writing key file "./example.net/dnskey.db" 145*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Incrementing serial number in file "./example.net/zone.db" 146*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Signing zone "example.net." 147*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 148*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.273: debug: Cmd dnssec-signzone return: "zone.db.signed" 149*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.273: debug: Signing completed after 0s. 150*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: Check RFC5011 status 151*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 152*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: Check KSK status 153*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: Check ZSK status 154*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: Lifetime(29100 sec) of depreciated key 33002 exceeded (300104 sec) 155*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: info: "example.net.": old ZSK 33002 removed 156*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.081: debug: ->remove it 157*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: debug: Re-signing necessary: Modfied zone key set 158*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: notice: "example.net.": re-signing triggered: Modfied zone key set 159*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: debug: Writing key file "./example.net/dnskey.db" 160*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: Incrementing serial number in file "./example.net/zone.db" 161*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: Signing zone "example.net." 162*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 163*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.173: debug: Cmd dnssec-signzone return: "zone.db.signed" 164*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.174: debug: Signing completed after 0s. 165*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: Check RFC5011 status 166*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 167*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: Check KSK status 168*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: Check ZSK status 169*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: Re-signing not necessary! 170*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: Check if there is a parent file to copy 171*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: Check RFC5011 status 172*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 173*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: Check KSK status 174*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: Check ZSK status 175*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: Re-signing necessary: re-signing interval (2d) reached 176*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached 177*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: Writing key file "./example.net/dnskey.db" 178*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.449: debug: Incrementing serial number in file "./example.net/zone.db" 179*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.449: debug: Signing zone "example.net." 180*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.450: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 181*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.530: debug: Cmd dnssec-signzone return: "zone.db.signed" 182*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.530: debug: Signing completed after 0s. 183*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: Check RFC5011 status 184*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 185*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: Check KSK status 186*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: Check ZSK status 187*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.416: debug: Re-signing not necessary! 188*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.416: debug: Check if there is a parent file to copy 189*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: Check RFC5011 status 190*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 191*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: Check KSK status 192*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: Check ZSK status 193*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: Lifetime(1209600 +/-150 sec) of active key 29240 exceeded (1333267 sec) 194*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: ->depreciate it 195*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: ->activate published key 5525 196*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: notice: "example.net.": lifetime of zone signing key 29240 exceeded: ZSK rollover done 197*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: New key for publishing needed 198*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: ->creating new key 21482 199*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: info: "example.net.": new key 21482 generated for publishing 200*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: Re-signing necessary: Modfied zone key set 201*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: notice: "example.net.": re-signing triggered: Modfied zone key set 202*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: Writing key file "././example.net/dnskey.db" 203*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: Incrementing serial number in file "././example.net/zone.db" 204*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: Signing zone "example.net." 205*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 206*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.294: debug: Cmd dnssec-signzone return: "zone.db.signed" 207*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.294: debug: Signing completed after 0s. 208*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: Check RFC5011 status 209*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 210*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: Check KSK status 211*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: Check ZSK status 212*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: Re-signing necessary: Modfied zone key set 213*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: notice: "example.net.": re-signing triggered: Modfied zone key set 214*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: Writing key file "././example.net/dnskey.db" 215*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: Incrementing serial number in file "././example.net/zone.db" 216*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: Signing zone "example.net." 217*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 218*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.278: debug: Cmd dnssec-signzone return: "zone.db.signed" 219*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.279: debug: Signing completed after 0s. 220*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: Check RFC5011 status 221*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 222*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: Check KSK status 223*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: Check ZSK status 224*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.985: debug: Re-signing not necessary! 225*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.985: debug: Check if there is a parent file to copy 226*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: Check RFC5011 status 227*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 228*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: Check KSK status 229*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: Check ZSK status 230*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: Re-signing not necessary! 231*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: Check if there is a parent file to copy 232*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: Check RFC5011 status 233*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 234*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: Check KSK status 235*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: Check ZSK status 236*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: Lifetime(29100 sec) of depreciated key 29240 exceeded (261285 sec) 237*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: info: "example.net.": old ZSK 29240 removed 238*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: ->remove it 239*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: Re-signing necessary: Modfied zone key set 240*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: notice: "example.net.": re-signing triggered: Modfied zone key set 241*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: Writing key file "./example.net/dnskey.db" 242*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: Incrementing serial number in file "./example.net/zone.db" 243*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: Signing zone "example.net." 244*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 245*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.929: debug: Cmd dnssec-signzone return: "zone.db.signed" 246*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.929: debug: Signing completed after 0s. 247*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.132: debug: Check RFC5011 status 248*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.132: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 249*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.133: debug: Check KSK status 250*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.133: debug: No active KSK found: generate new one 251*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: info: "example.net.": generated new KSK 8406 252*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: debug: Check ZSK status 253*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: debug: No active ZSK found: generate new one 254*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: info: "example.net.": generated new ZSK 36257 255*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: Re-signing necessary: Modfied zone key set 256*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: notice: "example.net.": re-signing triggered: Modfied zone key set 257*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: Writing key file "./example.net/dnskey.db" 258*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: Incrementing serial number in file "./example.net/zone.db" 259*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: Signing zone "example.net." 260*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 69AE05 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 261*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.408: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 generation requested with NSEC only DNSKEY" 262*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.408: error: "example.net.": signing failed! 263*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Check RFC5011 status 264*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 265*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Check KSK status 266*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Check ZSK status 267*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Re-signing necessary: Modified keys 268*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: notice: "example.net.": re-signing triggered: Modified keys 269*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Writing key file "./example.net/dnskey.db" 270*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Incrementing serial number in file "./example.net/zone.db" 271*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Signing zone "example.net." 272*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 67AA7F -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 273*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.920: debug: Cmd dnssec-signzone return: "zone.db.signed" 274*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.920: debug: Signing completed after 0s. 275*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: Check RFC5011 status 276*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 277*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: Check KSK status 278*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m44s 279*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: Check ZSK status 280*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081384 sec) 281*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: ->waiting for published key 282*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m44s: ZSK rollover deferred: waiting for published key 283*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: New key for publishing needed 284*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: ->creating new key 48476 285*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: info: "example.net.": new key 48476 generated for publishing 286*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: Re-signing necessary: Modfied zone key set 287*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: notice: "example.net.": re-signing triggered: Modfied zone key set 288*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: Writing key file "./example.net/dnskey.db" 289*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: Incrementing serial number in file "./example.net/zone.db" 290*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: Signing zone "example.net." 291*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5816F0 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 292*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.315: debug: Cmd dnssec-signzone return: "zone.db.signed" 293*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.315: debug: Signing completed after 0s. 294*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Check RFC5011 status 295*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 296*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Check KSK status 297*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m48s 298*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Check ZSK status 299*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081388 sec) 300*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: ->waiting for published key 301*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m48s: ZSK rollover deferred: waiting for published key 302*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Re-signing not necessary! 303*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: Check if there is a parent file to copy 304*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.502: debug: Check RFC5011 status 305*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.502: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 306*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: Check KSK status 307*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m18s 308*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: Check ZSK status 309*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081418 sec) 310*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: ->waiting for published key 311*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m18s: ZSK rollover deferred: waiting for published key 312*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: Re-signing not necessary! 313*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: Check if there is a parent file to copy 314*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Check RFC5011 status 315*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 316*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Check KSK status 317*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m24s 318*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Check ZSK status 319*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081424 sec) 320*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: ->waiting for published key 321*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m24s: ZSK rollover deferred: waiting for published key 322*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Re-signing necessary: Option -f 323*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: notice: "example.net.": re-signing triggered: Option -f 324*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Writing key file "./example.net/dnskey.db" 325*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Incrementing serial number in file "./example.net/zone.db" 326*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Signing zone "example.net." 327*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 C58544 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 328*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.993: debug: Cmd dnssec-signzone return: "zone.db.signed" 329*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.993: debug: Signing completed after 0s. 330*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Check RFC5011 status 331*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 332*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Check KSK status 333*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m53s 334*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Check ZSK status 335*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081453 sec) 336*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: ->waiting for published key 337*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m53s: ZSK rollover deferred: waiting for published key 338*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Re-signing necessary: Option -f 339*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: notice: "example.net.": re-signing triggered: Option -f 340*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: Writing key file "./example.net/dnskey.db" 341*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: Incrementing serial number in file "./example.net/zone.db" 342*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: Signing zone "example.net." 343*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 FCB8E2 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 344*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.648: debug: Cmd dnssec-signzone return: "zone.db.signed" 345*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.648: debug: Signing completed after 0s. 346*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: Check RFC5011 status 347*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 348*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: Check KSK status 349*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: Check ZSK status 350*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (2130473 sec) 351*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: ->depreciate it 352*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: ->activate published key 48476 353*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: notice: "example.net.": lifetime of zone signing key 36257 exceeded: ZSK rollover done 354*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: New key for publishing needed 355*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: ->creating new key 1775 356*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: info: "example.net.": new key 1775 generated for publishing 357*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: Re-signing necessary: Modfied zone key set 358*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: notice: "example.net.": re-signing triggered: Modfied zone key set 359*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: Writing key file "./example.net/dnskey.db" 360*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: Incrementing serial number in file "./example.net/zone.db" 361*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: Signing zone "example.net." 362*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.494: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 3723BA -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 363*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.563: debug: Cmd dnssec-signzone return: "zone.db.signed" 364*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.563: debug: Signing completed after 0s. 365*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: Check RFC5011 status 366*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 367*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: Check KSK status 368*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: Check ZSK status 369*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: Lifetime(29100 sec) of depreciated key 36257 exceeded (2409674 sec) 370*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: info: "example.net.": old ZSK 36257 removed 371*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: ->remove it 372*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: Lifetime(1209600 +/-150 sec) of active key 48476 exceeded (2409674 sec) 373*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: ->depreciate it 374*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: ->activate published key 1775 375*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: notice: "example.net.": lifetime of zone signing key 48476 exceeded: ZSK rollover done 376*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: New key for publishing needed 377*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: ->creating new key 26477 378*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: info: "example.net.": new key 26477 generated for publishing 379*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: Re-signing necessary: Modfied zone key set 380*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: notice: "example.net.": re-signing triggered: Modfied zone key set 381*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: Writing key file "./example.net/dnskey.db" 382*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: Incrementing serial number in file "./example.net/zone.db" 383*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: Signing zone "example.net." 384*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 2F41F9 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 385*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.704: debug: Cmd dnssec-signzone return: "zone.db.signed" 386*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.704: debug: Signing completed after 0s. 387*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: Check RFC5011 status 388*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 389*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: Check KSK status 390*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: Check ZSK status 391*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: Re-signing not necessary! 392*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: Check if there is a parent file to copy 393*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: Check RFC5011 status 394*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 395*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: Check KSK status 396*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: Check ZSK status 397*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: New key for publishing needed 398*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: ->creating new key 18026 399*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: info: "example.net.": new key 18026 generated for publishing 400*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: Re-signing necessary: Modfied zone key set 401*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: notice: "example.net.": re-signing triggered: Modfied zone key set 402*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: Writing key file "./example.net/dnskey.db" 403*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: Incrementing serial number in file "./example.net/zone.db" 404*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: Signing zone "example.net." 405*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5EA89E -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 406*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.672: debug: Cmd dnssec-signzone return: "zone.db.signed" 407*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.672: debug: Signing completed after 0s. 408*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.808: debug: Check RFC5011 status 409*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.808: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 410*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: Check KSK status 411*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: Check ZSK status 412*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: Re-signing not necessary! 413*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: Check if there is a parent file to copy 414*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: Check RFC5011 status 415*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 416*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: Check KSK status 417*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: Check ZSK status 418*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: Re-signing not necessary! 419*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: Check if there is a parent file to copy 420*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: Check RFC5011 status 421*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 422*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: Check KSK status 423*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: Check ZSK status 424*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: Re-signing not necessary! 425*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: Check if there is a parent file to copy 426*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: Check RFC5011 status 427*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 428*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: Check KSK status 429*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: Check ZSK status 430*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.725: debug: Re-signing not necessary! 431*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.725: debug: Check if there is a parent file to copy 432*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: Check RFC5011 status 433*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 434*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: Check KSK status 435*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: Check ZSK status 436*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: Re-signing not necessary! 437*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: Check if there is a parent file to copy 438*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: Check RFC5011 status 439*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 440*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: Check KSK status 441*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: Check ZSK status 442*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: Re-signing not necessary! 443*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: Check if there is a parent file to copy 444*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: Check RFC5011 status 445*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 446*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: Check KSK status 447*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: Check ZSK status 448*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: Re-signing not necessary! 449*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.825: debug: Check if there is a parent file to copy 450*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: Check RFC5011 status 451*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 452*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: Check KSK status 453*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: Check ZSK status 454*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: New key for pre-publishing needed 455*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: ->creating new key 18293 456*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: info: "example.net.": new key 18293 generated for pre-publishing 457*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: Re-signing necessary: Modfied zone key set 458*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: notice: "example.net.": re-signing triggered: Modfied zone key set 459*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: Writing key file "./example.net/dnskey.db" 460*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: Incrementing serial number in file "./example.net/zone.db" 461*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: Signing zone "example.net." 462*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.111: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 EBE919 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 463*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.168: debug: Cmd dnssec-signzone return: "zone.db.signed" 464*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.169: debug: Signing completed after 0s. 465*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: Check RFC5011 status 466*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 467*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: Check KSK status 468*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: Check ZSK status 469*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: Re-signing necessary: Modfied zone key set 470*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: notice: "example.net.": re-signing triggered: Modfied zone key set 471*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: Writing key file "./example.net/dnskey.db" 472*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: Incrementing serial number in file "./example.net/zone.db" 473*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: Signing zone "example.net." 474*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 A876E5 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 475*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.531: debug: Cmd dnssec-signzone return: "zone.db.signed" 476*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.531: debug: Signing completed after 0s. 477*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: Check RFC5011 status 478*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 479*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: Check KSK status 480*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: Check ZSK status 481*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: Re-signing not necessary! 482*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: Check if there is a parent file to copy 483*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: Check RFC5011 status 484*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 485*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: Check KSK status 486*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: Check ZSK status 487*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: Re-signing necessary: re-signing interval (2d) reached 488*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached 489*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: Writing key file "./example.net/dnskey.db" 490*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: Incrementing serial number in file "./example.net/zone.db" 491*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: Signing zone "example.net." 492*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9FC981 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 493*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.761: debug: Cmd dnssec-signzone return: "zone.db.signed" 494*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.761: debug: Signing completed after 0s. 495*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: Check RFC5011 status 496*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 497*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: Check KSK status 498*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: Check ZSK status 499*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: Re-signing not necessary! 500*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: Check if there is a parent file to copy 501*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: Check RFC5011 status 502*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 503*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: Check KSK status 504*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: Check ZSK status 505*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: Re-signing not necessary! 506*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: Check if there is a parent file to copy 507*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: Check RFC5011 status 508*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 509*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: Check KSK status 510*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: Check ZSK status 511*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: Re-signing not necessary! 512*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: Check if there is a parent file to copy 513*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: Check RFC5011 status 514*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 515*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: Check KSK status 516*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: Check ZSK status 517*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: Re-signing necessary: Modified keys 518*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: notice: "example.net.": re-signing triggered: Modified keys 519*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: Writing key file "./example.net/dnskey.db" 520*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: Incrementing serial number in file "./example.net/zone.db" 521*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: Signing zone "example.net." 522*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 97195D -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 523*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.827: debug: Cmd dnssec-signzone return: "zone.db.signed" 524*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.827: debug: Signing completed after 0s. 525*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: Check RFC5011 status 526*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 527*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: Check KSK status 528*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.428: debug: No active KSK found: generate new one 529*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: info: "example.net.": generated new KSK 44671 530*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: debug: Check ZSK status 531*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: debug: No active ZSK found: generate new one 532*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.515: info: "example.net.": generated new ZSK 7929 533*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.515: debug: New key for pre-publishing needed 534*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: debug: ->creating new key 2253 535*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: info: "example.net.": new key 2253 generated for pre-publishing 536*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: debug: Re-signing necessary: Modified zone key set 537*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: notice: "example.net.": re-signing triggered: Modified zone key set 538*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: Writing key file "./example.net/dnskey.db" 539*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: Incrementing serial number in file "./example.net/zone.db" 540*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: Signing zone "example.net." 541*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 B26BB7 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 542*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.646: debug: Cmd dnssec-signzone return: "zone.db.signed" 543*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.646: debug: Signing completed after 0s. 544*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: Check RFC5011 status 545*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 546*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: Check KSK status 547*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: Check ZSK status 548*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: Re-signing not necessary! 549*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: Check if there is a parent file to copy 550*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: Check RFC5011 status 551*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 552*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: Check KSK status 553*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: Check ZSK status 554*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: Re-signing not necessary! 555*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: Check if there is a parent file to copy 556*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: Check RFC5011 status 557*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 558*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: Check KSK status 559*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: Check ZSK status 560*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: Re-signing not necessary! 561*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: Check if there is a parent file to copy 562*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: Check RFC5011 status 563*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 564*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: Check KSK status 565*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: Check ZSK status 566*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: Re-signing necessary: Modified keys 567*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: notice: "example.net.": re-signing triggered: Modified keys 568*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: Writing key file "././example.net/dnskey.db" 569*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: Incrementing serial number in file "././example.net/zone.db" 570*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: Signing zone "example.net." 571*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 8B4599 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 572*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.488: debug: Cmd dnssec-signzone return: "zone.db.signed" 573*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.488: debug: Signing completed after 0s. 574*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: Check RFC5011 status 575*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 576*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: Check KSK status 577*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: Check ZSK status 578*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: Re-signing not necessary! 579*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: Check if there is a parent file to copy 580*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Check RFC5011 status 581*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 582*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Check KSK status 583*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Check ZSK status 584*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Re-signing necessary: Modified keys 585*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: notice: "example.net.": re-signing triggered: Modified keys 586*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Writing key file "././example.net/dnskey.db" 587*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Incrementing serial number in file "././example.net/zone.db" 588*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Signing zone "example.net." 589*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 BEBFB0 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 590*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.484: debug: Cmd dnssec-signzone return: "zone.db.signed" 591*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.484: debug: Signing completed after 0s. 592*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: Check RFC5011 status 593*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 594*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: Check KSK status 595*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: Check ZSK status 596*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: Re-signing necessary: Modified keys 597*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: notice: "example.net.": re-signing triggered: Modified keys 598*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: Writing key file "././example.net/dnskey.db" 599*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: Incrementing serial number in file "././example.net/zone.db" 600*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: Signing zone "example.net." 601*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 DC5680 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 602*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.715: debug: Cmd dnssec-signzone return: "zone.db.signed" 603*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.715: debug: Signing completed after 0s. 604*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: Check RFC5011 status 605*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 606*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: Check KSK status 607*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: Check ZSK status 608*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: Re-signing not necessary! 609*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: Check if there is a parent file to copy 610*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Check RFC5011 status 611*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 612*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Check KSK status 613*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Check ZSK status 614*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Re-signing necessary: Modified keys 615*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: notice: "example.net.": re-signing triggered: Modified keys 616*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Writing key file "././example.net/dnskey.db" 617*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Incrementing serial number in file "././example.net/zone.db" 618*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Signing zone "example.net." 619*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 D82F90 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 620*00b67f09SDavid van Moolenbroek2014-11-15 18:17:07.040: debug: Cmd dnssec-signzone return: "zone.db.signed" 621*00b67f09SDavid van Moolenbroek2014-11-15 18:17:07.040: debug: Signing completed after 1s. 622*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: Check RFC5011 status 623*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 624*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: Check KSK status 625*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Check ZSK status 626*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Re-signing necessary: Zone file edited 627*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: notice: "example.net.": re-signing triggered: Zone file edited 628*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Writing key file "././example.net/dnskey.db" 629*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Incrementing serial number in file "././example.net/zone.db" 630*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Signing zone "example.net." 631*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 603310 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 632*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.365: debug: Cmd dnssec-signzone return: "zone.db.signed" 633*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.365: debug: Signing completed after 0s. 634*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: Check RFC5011 status 635*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 636*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: Check KSK status 637*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: Check ZSK status 638*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: Re-signing necessary: re-signing interval (2d) reached 639*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached 640*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: Writing key file "./example.net/dnskey.db" 641*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: Incrementing serial number in file "./example.net/zone.db" 642*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: Signing zone "example.net." 643*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9F5882 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 644*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.392: debug: Cmd dnssec-signzone return: "zone.db.signed" 645*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.392: debug: Signing completed after 0s. 646*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: Check RFC5011 status 647*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 648*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: Check KSK status 649*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: Check ZSK status 650*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: Re-signing not necessary! 651*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: Check if there is a parent file to copy 652*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: Check RFC5011 status 653*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 654*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: Check KSK status 655*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: Check ZSK status 656*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: Re-signing not necessary! 657*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: Check if there is a parent file to copy 658*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Check RFC5011 status 659*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 660*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Check KSK status 661*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Check ZSK status 662*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Re-signing necessary: Modified keys 663*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: notice: "example.net.": re-signing triggered: Modified keys 664*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Writing key file "./example.net/dnskey.db" 665*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Incrementing serial number in file "./example.net/zone.db" 666*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: Signing zone "example.net." 667*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.411: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 053453 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 668*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.525: debug: Cmd dnssec-signzone return: "zone.db.signed" 669*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.525: debug: Signing completed after 0s. 670*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: Check RFC5011 status 671*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 672*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: Check KSK status 673*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: Check ZSK status 674*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: Re-signing not necessary! 675*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: Check if there is a parent file to copy 676*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Check RFC5011 status 677*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: ->not a rfc5011 zone, looking for a regular ksk rollover 678*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Check KSK status 679*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Check ZSK status 680*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Re-signing necessary: Zone file edited 681*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: notice: "example.net.": re-signing triggered: Zone file edited 682*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Writing key file "./example.net/dnskey.db" 683*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Incrementing serial number in file "./example.net/zone.db" 684*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: Signing zone "example.net." 685*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.847: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 7CF530 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1" 686*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.969: debug: Cmd dnssec-signzone return: "zone.db.signed" 687*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.969: debug: Signing completed after 0s. 688