xref: /minix3/external/bsd/bind/dist/contrib/zkt-1.1.3/examples/flat/example.net/zktlog-example.net. (revision 00b67f09dd46474d133c95011a48590a8e8f94c7)
1*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 	Check RFC5011 status
2*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
3*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 	Check KSK status
4*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 	Check ZSK status
5*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 	Re-signing not necessary!
6*00b67f09SDavid van Moolenbroek2010-02-06 00:26:54.533: debug: 	Check if there is a parent file to copy
7*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: 	Check RFC5011 status
8*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
9*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.291: debug: 	Check KSK status
10*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: 	Check ZSK status
11*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: 	Re-signing not necessary!
12*00b67f09SDavid van Moolenbroek2010-02-06 00:29:31.292: debug: 	Check if there is a parent file to copy
13*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 	Check RFC5011 status
14*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
15*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 	Check KSK status
16*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 	Check ZSK status
17*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 	Re-signing not necessary!
18*00b67f09SDavid van Moolenbroek2010-02-06 00:40:35.043: debug: 	Check if there is a parent file to copy
19*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 	Check RFC5011 status
20*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
21*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 	Check KSK status
22*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 	Check ZSK status
23*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 	Re-signing not necessary!
24*00b67f09SDavid van Moolenbroek2010-02-06 00:52:55.403: debug: 	Check if there is a parent file to copy
25*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 	Check RFC5011 status
26*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
27*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 	Check KSK status
28*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 	Check ZSK status
29*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 	Re-signing not necessary!
30*00b67f09SDavid van Moolenbroek2010-02-07 13:53:48.304: debug: 	Check if there is a parent file to copy
31*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 	Check RFC5011 status
32*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
33*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 	Check KSK status
34*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 	Check ZSK status
35*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 	Re-signing not necessary!
36*00b67f09SDavid van Moolenbroek2010-02-07 13:54:03.466: debug: 	Check if there is a parent file to copy
37*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.019: debug: 	Check RFC5011 status
38*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.019: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
39*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Check KSK status
40*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Check ZSK status
41*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Re-signing necessary: Option -f
42*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: notice: "example.net.": re-signing triggered: Option -f
43*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Writing key file "./example.net/dnskey.db"
44*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Incrementing serial number in file "./example.net/zone.db"
45*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.020: debug: 	Signing zone "example.net."
46*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.021: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
47*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
48*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: 	Signing completed after 0s.
49*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: notice: "example.net.": distribution triggered
50*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: 	Distribute zone "example.net."
51*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.125: debug: 	  Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed "
52*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: 	  ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./"
53*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: notice: "example.net.": reload triggered
54*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: 	Reload zone "example.net."
55*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.129: debug: 	  Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed "
56*00b67f09SDavid van Moolenbroek2010-02-07 13:54:08.139: debug: 	  ./dist.sh reload return: "rndc reload example.net. "
57*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: 	Check RFC5011 status
58*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
59*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: 	Check KSK status
60*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: 	Check ZSK status
61*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.670: debug: 	Re-signing not necessary!
62*00b67f09SDavid van Moolenbroek2010-02-07 14:06:27.671: debug: 	Check if there is a parent file to copy
63*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 	Check RFC5011 status
64*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
65*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 	Check KSK status
66*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 	Check ZSK status
67*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 	Re-signing necessary: Option -f
68*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: notice: "example.net.": re-signing triggered: Option -f
69*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.753: debug: 	Writing key file "./example.net/dnskey.db"
70*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: 	Incrementing serial number in file "./example.net/zone.db"
71*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: 	Signing zone "example.net."
72*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.754: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
73*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
74*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: 	Signing completed after 0s.
75*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: notice: "example.net.": distribution triggered
76*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: 	Distribute zone "example.net."
77*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.790: debug: 	  Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed "
78*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: 	  ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./"
79*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: notice: "example.net.": reload triggered
80*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: 	Reload zone "example.net."
81*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.794: debug: 	  Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed "
82*00b67f09SDavid van Moolenbroek2010-02-07 14:06:33.797: debug: 	  ./dist.sh reload return: "rndc reload example.net. "
83*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 	Check RFC5011 status
84*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
85*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 	Check KSK status
86*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 	Check ZSK status
87*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 	Lifetime(1209600 +/-150 sec) of active key 33002 exceeded (2394625 sec)
88*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 		->depreciate it
89*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 		->activate published key 29240
90*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: notice: "example.net.": lifetime of zone signing key 33002 exceeded: ZSK rollover done
91*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.587: debug: 	New key for publishing needed
92*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: 		->creating new key 5525
93*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: info: "example.net.": new key 5525 generated for publishing
94*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: 	Re-signing necessary: Modfied zone key set
95*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: notice: "example.net.": re-signing triggered: Modfied zone key set
96*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.658: debug: 	Writing key file "./example.net/dnskey.db"
97*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: 	Incrementing serial number in file "./example.net/zone.db"
98*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: 	Signing zone "example.net."
99*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.665: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
100*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.733: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
101*00b67f09SDavid van Moolenbroek2010-02-21 12:50:43.733: debug: 	Signing completed after 0s.
102*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 	Check RFC5011 status
103*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
104*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 	Check KSK status
105*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 	Check ZSK status
106*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 	Re-signing not necessary!
107*00b67f09SDavid van Moolenbroek2010-02-21 12:50:51.205: debug: 	Check if there is a parent file to copy
108*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 	Check RFC5011 status
109*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
110*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 	Check KSK status
111*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 	Check ZSK status
112*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 	Re-signing not necessary!
113*00b67f09SDavid van Moolenbroek2010-02-21 12:51:23.497: debug: 	Check if there is a parent file to copy
114*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 	Check RFC5011 status
115*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
116*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 	Check KSK status
117*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 	Check ZSK status
118*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 	Re-signing not necessary!
119*00b67f09SDavid van Moolenbroek2010-02-21 19:16:18.594: debug: 	Check if there is a parent file to copy
120*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 	Check RFC5011 status
121*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
122*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 	Check KSK status
123*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 	Check ZSK status
124*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 	Re-signing not necessary!
125*00b67f09SDavid van Moolenbroek2010-02-21 19:32:11.378: debug: 	Check if there is a parent file to copy
126*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Check RFC5011 status
127*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
128*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Check KSK status
129*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Check ZSK status
130*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Re-signing necessary: Option -f
131*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: notice: "example.net.": re-signing triggered: Option -f
132*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Writing key file "./example.net/dnskey.db"
133*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Incrementing serial number in file "./example.net/zone.db"
134*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	Signing zone "example.net."
135*00b67f09SDavid van Moolenbroek2010-02-21 19:32:15.982: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
136*00b67f09SDavid van Moolenbroek2010-02-21 19:32:16.019: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
137*00b67f09SDavid van Moolenbroek2010-02-21 19:32:16.019: debug: 	Signing completed after 1s.
138*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.232: debug: 	Check RFC5011 status
139*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.232: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
140*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Check KSK status
141*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Check ZSK status
142*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Re-signing necessary: Option -f
143*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: notice: "example.net.": re-signing triggered: Option -f
144*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Writing key file "./example.net/dnskey.db"
145*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Incrementing serial number in file "./example.net/zone.db"
146*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	Signing zone "example.net."
147*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.233: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
148*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.273: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
149*00b67f09SDavid van Moolenbroek2010-02-21 19:32:32.273: debug: 	Signing completed after 0s.
150*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: 	Check RFC5011 status
151*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
152*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: 	Check KSK status
153*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: 	Check ZSK status
154*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: debug: 	Lifetime(29100 sec) of depreciated key 33002 exceeded (300104 sec)
155*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.060: info: "example.net.": old ZSK 33002 removed
156*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.081: debug: 		->remove it
157*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: debug: 	Re-signing necessary: Modfied zone key set
158*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: notice: "example.net.": re-signing triggered: Modfied zone key set
159*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.082: debug: 	Writing key file "./example.net/dnskey.db"
160*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: 	Incrementing serial number in file "./example.net/zone.db"
161*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: 	Signing zone "example.net."
162*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.086: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
163*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.173: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
164*00b67f09SDavid van Moolenbroek2010-02-25 00:12:27.174: debug: 	Signing completed after 0s.
165*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 	Check RFC5011 status
166*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
167*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 	Check KSK status
168*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 	Check ZSK status
169*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 	Re-signing not necessary!
170*00b67f09SDavid van Moolenbroek2010-02-25 23:42:21.013: debug: 	Check if there is a parent file to copy
171*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 	Check RFC5011 status
172*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
173*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 	Check KSK status
174*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 	Check ZSK status
175*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 	Re-signing necessary: re-signing interval (2d) reached
176*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
177*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.416: debug: 	Writing key file "./example.net/dnskey.db"
178*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.449: debug: 	Incrementing serial number in file "./example.net/zone.db"
179*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.449: debug: 	Signing zone "example.net."
180*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.450: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
181*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.530: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
182*00b67f09SDavid van Moolenbroek2010-03-02 10:59:12.530: debug: 	Signing completed after 0s.
183*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: 	Check RFC5011 status
184*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
185*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: 	Check KSK status
186*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.415: debug: 	Check ZSK status
187*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.416: debug: 	Re-signing not necessary!
188*00b67f09SDavid van Moolenbroek2010-03-03 23:22:00.416: debug: 	Check if there is a parent file to copy
189*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: 	Check RFC5011 status
190*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
191*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: 	Check KSK status
192*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.170: debug: 	Check ZSK status
193*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: 	Lifetime(1209600 +/-150 sec) of active key 29240 exceeded (1333267 sec)
194*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: 		->depreciate it
195*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: 		->activate published key 5525
196*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: notice: "example.net.": lifetime of zone signing key 29240 exceeded: ZSK rollover done
197*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.171: debug: 	New key for publishing needed
198*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: 		->creating new key 21482
199*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: info: "example.net.": new key 21482 generated for publishing
200*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: 	Re-signing necessary: Modfied zone key set
201*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: notice: "example.net.": re-signing triggered: Modfied zone key set
202*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.228: debug: 	Writing key file "././example.net/dnskey.db"
203*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: 	Incrementing serial number in file "././example.net/zone.db"
204*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: 	Signing zone "example.net."
205*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.235: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
206*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.294: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
207*00b67f09SDavid van Moolenbroek2010-03-08 23:11:50.294: debug: 	Signing completed after 0s.
208*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 	Check RFC5011 status
209*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
210*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 	Check KSK status
211*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 	Check ZSK status
212*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 	Re-signing necessary: Modfied zone key set
213*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: notice: "example.net.": re-signing triggered: Modfied zone key set
214*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.212: debug: 	Writing key file "././example.net/dnskey.db"
215*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: 	Incrementing serial number in file "././example.net/zone.db"
216*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: 	Signing zone "example.net."
217*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.213: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
218*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.278: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
219*00b67f09SDavid van Moolenbroek2010-03-08 23:12:56.279: debug: 	Signing completed after 0s.
220*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: 	Check RFC5011 status
221*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
222*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: 	Check KSK status
223*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.984: debug: 	Check ZSK status
224*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.985: debug: 	Re-signing not necessary!
225*00b67f09SDavid van Moolenbroek2010-03-08 23:13:36.985: debug: 	Check if there is a parent file to copy
226*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 	Check RFC5011 status
227*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
228*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 	Check KSK status
229*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 	Check ZSK status
230*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 	Re-signing not necessary!
231*00b67f09SDavid van Moolenbroek2010-03-08 23:18:52.287: debug: 	Check if there is a parent file to copy
232*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: 	Check RFC5011 status
233*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
234*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: 	Check KSK status
235*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: 	Check ZSK status
236*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: debug: 	Lifetime(29100 sec) of depreciated key 29240 exceeded (261285 sec)
237*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.831: info: "example.net.": old ZSK 29240 removed
238*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: 		->remove it
239*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: 	Re-signing necessary: Modfied zone key set
240*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: notice: "example.net.": re-signing triggered: Modfied zone key set
241*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.832: debug: 	Writing key file "./example.net/dnskey.db"
242*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: 	Incrementing serial number in file "./example.net/zone.db"
243*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: 	Signing zone "example.net."
244*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.841: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
245*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.929: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
246*00b67f09SDavid van Moolenbroek2010-03-11 23:46:35.929: debug: 	Signing completed after 0s.
247*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.132: debug: 	Check RFC5011 status
248*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.132: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
249*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.133: debug: 	Check KSK status
250*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.133: debug: 	No active KSK found: generate new one
251*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: info: "example.net.": generated new KSK 8406
252*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: debug: 	Check ZSK status
253*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.374: debug: 	No active ZSK found: generate new one
254*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: info: "example.net.": generated new ZSK 36257
255*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: 	Re-signing necessary: Modfied zone key set
256*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: notice: "example.net.": re-signing triggered: Modfied zone key set
257*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: 	Writing key file "./example.net/dnskey.db"
258*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: 	Incrementing serial number in file "./example.net/zone.db"
259*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: 	Signing zone "example.net."
260*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.400: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 69AE05 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
261*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.408: debug: 	  Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 generation requested with NSEC only DNSKEY"
262*00b67f09SDavid van Moolenbroek2010-03-11 23:52:33.408: error: "example.net.": signing failed!
263*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Check RFC5011 status
264*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
265*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Check KSK status
266*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Check ZSK status
267*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Re-signing necessary: Modified keys
268*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: notice: "example.net.": re-signing triggered: Modified keys
269*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Writing key file "./example.net/dnskey.db"
270*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Incrementing serial number in file "./example.net/zone.db"
271*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	Signing zone "example.net."
272*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.856: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 67AA7F -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
273*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.920: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
274*00b67f09SDavid van Moolenbroek2010-03-11 23:53:27.920: debug: 	Signing completed after 0s.
275*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 	Check RFC5011 status
276*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
277*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 	Check KSK status
278*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m44s
279*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 	Check ZSK status
280*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081384 sec)
281*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 		->waiting for published key
282*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m44s: ZSK rollover deferred: waiting for published key
283*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.179: debug: 	New key for publishing needed
284*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 		->creating new key 48476
285*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: info: "example.net.": new key 48476 generated for publishing
286*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 	Re-signing necessary: Modfied zone key set
287*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: notice: "example.net.": re-signing triggered: Modfied zone key set
288*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 	Writing key file "./example.net/dnskey.db"
289*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 	Incrementing serial number in file "./example.net/zone.db"
290*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 	Signing zone "example.net."
291*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.278: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5816F0 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
292*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.315: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
293*00b67f09SDavid van Moolenbroek2010-07-05 08:15:24.315: debug: 	Signing completed after 0s.
294*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Check RFC5011 status
295*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
296*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Check KSK status
297*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m48s
298*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Check ZSK status
299*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081388 sec)
300*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 		->waiting for published key
301*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m48s: ZSK rollover deferred: waiting for published key
302*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Re-signing not necessary!
303*00b67f09SDavid van Moolenbroek2010-07-05 08:15:28.174: debug: 	Check if there is a parent file to copy
304*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.502: debug: 	Check RFC5011 status
305*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.502: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
306*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 	Check KSK status
307*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m18s
308*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 	Check ZSK status
309*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081418 sec)
310*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 		->waiting for published key
311*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m18s: ZSK rollover deferred: waiting for published key
312*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 	Re-signing not necessary!
313*00b67f09SDavid van Moolenbroek2010-07-05 08:15:58.503: debug: 	Check if there is a parent file to copy
314*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Check RFC5011 status
315*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
316*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Check KSK status
317*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m24s
318*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Check ZSK status
319*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081424 sec)
320*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 		->waiting for published key
321*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m24s: ZSK rollover deferred: waiting for published key
322*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Re-signing necessary: Option -f
323*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: notice: "example.net.": re-signing triggered: Option -f
324*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Writing key file "./example.net/dnskey.db"
325*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Incrementing serial number in file "./example.net/zone.db"
326*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	Signing zone "example.net."
327*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.937: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 C58544 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
328*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.993: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
329*00b67f09SDavid van Moolenbroek2010-07-05 08:16:04.993: debug: 	Signing completed after 0s.
330*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Check RFC5011 status
331*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
332*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Check KSK status
333*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m53s
334*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Check ZSK status
335*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081453 sec)
336*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 		->waiting for published key
337*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m53s: ZSK rollover deferred: waiting for published key
338*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Re-signing necessary: Option -f
339*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: notice: "example.net.": re-signing triggered: Option -f
340*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.604: debug: 	Writing key file "./example.net/dnskey.db"
341*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: 	Incrementing serial number in file "./example.net/zone.db"
342*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: 	Signing zone "example.net."
343*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.605: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 FCB8E2 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
344*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.648: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
345*00b67f09SDavid van Moolenbroek2010-07-05 08:16:33.648: debug: 	Signing completed after 0s.
346*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 	Check RFC5011 status
347*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
348*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 	Check KSK status
349*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 	Check ZSK status
350*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 	Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (2130473 sec)
351*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 		->depreciate it
352*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 		->activate published key 48476
353*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: notice: "example.net.": lifetime of zone signing key 36257 exceeded: ZSK rollover done
354*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.411: debug: 	New key for publishing needed
355*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: 		->creating new key 1775
356*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: info: "example.net.": new key 1775 generated for publishing
357*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: 	Re-signing necessary: Modfied zone key set
358*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: notice: "example.net.": re-signing triggered: Modfied zone key set
359*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: 	Writing key file "./example.net/dnskey.db"
360*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: 	Incrementing serial number in file "./example.net/zone.db"
361*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.493: debug: 	Signing zone "example.net."
362*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.494: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 3723BA -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
363*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.563: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
364*00b67f09SDavid van Moolenbroek2010-07-30 01:30:55.563: debug: 	Signing completed after 0s.
365*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: 	Check RFC5011 status
366*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
367*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: 	Check KSK status
368*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: 	Check ZSK status
369*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: debug: 	Lifetime(29100 sec) of depreciated key 36257 exceeded (2409674 sec)
370*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.539: info: "example.net.": old ZSK 36257 removed
371*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: 		->remove it
372*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: 	Lifetime(1209600 +/-150 sec) of active key 48476 exceeded (2409674 sec)
373*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: 		->depreciate it
374*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: 		->activate published key 1775
375*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: notice: "example.net.": lifetime of zone signing key 48476 exceeded: ZSK rollover done
376*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.572: debug: 	New key for publishing needed
377*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: 		->creating new key 26477
378*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: info: "example.net.": new key 26477 generated for publishing
379*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: 	Re-signing necessary: Modfied zone key set
380*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: notice: "example.net.": re-signing triggered: Modfied zone key set
381*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.640: debug: 	Writing key file "./example.net/dnskey.db"
382*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: 	Incrementing serial number in file "./example.net/zone.db"
383*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: 	Signing zone "example.net."
384*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.641: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 2F41F9 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
385*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.704: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
386*00b67f09SDavid van Moolenbroek2010-08-26 22:52:09.704: debug: 	Signing completed after 0s.
387*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 	Check RFC5011 status
388*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
389*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 	Check KSK status
390*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 	Check ZSK status
391*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 	Re-signing not necessary!
392*00b67f09SDavid van Moolenbroek2010-08-26 22:56:02.938: debug: 	Check if there is a parent file to copy
393*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: 	Check RFC5011 status
394*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
395*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: 	Check KSK status
396*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: 	Check ZSK status
397*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.593: debug: 	New key for publishing needed
398*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 		->creating new key 18026
399*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: info: "example.net.": new key 18026 generated for publishing
400*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 	Re-signing necessary: Modfied zone key set
401*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: notice: "example.net.": re-signing triggered: Modfied zone key set
402*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 	Writing key file "./example.net/dnskey.db"
403*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 	Incrementing serial number in file "./example.net/zone.db"
404*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 	Signing zone "example.net."
405*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.631: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5EA89E -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
406*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.672: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
407*00b67f09SDavid van Moolenbroek2010-08-26 23:06:00.672: debug: 	Signing completed after 0s.
408*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.808: debug: 	Check RFC5011 status
409*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.808: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
410*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: 	Check KSK status
411*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: 	Check ZSK status
412*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: 	Re-signing not necessary!
413*00b67f09SDavid van Moolenbroek2010-08-26 23:11:33.809: debug: 	Check if there is a parent file to copy
414*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 	Check RFC5011 status
415*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
416*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 	Check KSK status
417*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 	Check ZSK status
418*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 	Re-signing not necessary!
419*00b67f09SDavid van Moolenbroek2010-08-26 23:12:51.012: debug: 	Check if there is a parent file to copy
420*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 	Check RFC5011 status
421*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
422*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 	Check KSK status
423*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 	Check ZSK status
424*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 	Re-signing not necessary!
425*00b67f09SDavid van Moolenbroek2010-08-26 23:23:47.886: debug: 	Check if there is a parent file to copy
426*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: 	Check RFC5011 status
427*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
428*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: 	Check KSK status
429*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.724: debug: 	Check ZSK status
430*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.725: debug: 	Re-signing not necessary!
431*00b67f09SDavid van Moolenbroek2010-08-26 23:50:15.725: debug: 	Check if there is a parent file to copy
432*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 	Check RFC5011 status
433*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
434*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 	Check KSK status
435*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 	Check ZSK status
436*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 	Re-signing not necessary!
437*00b67f09SDavid van Moolenbroek2010-08-26 23:50:55.124: debug: 	Check if there is a parent file to copy
438*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 	Check RFC5011 status
439*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
440*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 	Check KSK status
441*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 	Check ZSK status
442*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 	Re-signing not necessary!
443*00b67f09SDavid van Moolenbroek2010-08-26 23:51:46.719: debug: 	Check if there is a parent file to copy
444*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: 	Check RFC5011 status
445*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
446*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: 	Check KSK status
447*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: 	Check ZSK status
448*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.824: debug: 	Re-signing not necessary!
449*00b67f09SDavid van Moolenbroek2010-08-26 23:54:22.825: debug: 	Check if there is a parent file to copy
450*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: 	Check RFC5011 status
451*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
452*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: 	Check KSK status
453*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: 	Check ZSK status
454*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.018: debug: 	New key for pre-publishing needed
455*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: 		->creating new key 18293
456*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: info: "example.net.": new key 18293 generated for pre-publishing
457*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: 	Re-signing necessary: Modfied zone key set
458*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: notice: "example.net.": re-signing triggered: Modfied zone key set
459*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: 	Writing key file "./example.net/dnskey.db"
460*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: 	Incrementing serial number in file "./example.net/zone.db"
461*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.110: debug: 	Signing zone "example.net."
462*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.111: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 EBE919 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
463*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.168: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
464*00b67f09SDavid van Moolenbroek2010-08-26 23:55:00.169: debug: 	Signing completed after 0s.
465*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 	Check RFC5011 status
466*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
467*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 	Check KSK status
468*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 	Check ZSK status
469*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 	Re-signing necessary: Modfied zone key set
470*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: notice: "example.net.": re-signing triggered: Modfied zone key set
471*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.466: debug: 	Writing key file "./example.net/dnskey.db"
472*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: 	Incrementing serial number in file "./example.net/zone.db"
473*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: 	Signing zone "example.net."
474*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.467: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 A876E5 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
475*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.531: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
476*00b67f09SDavid van Moolenbroek2010-08-26 23:56:17.531: debug: 	Signing completed after 0s.
477*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 	Check RFC5011 status
478*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
479*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 	Check KSK status
480*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 	Check ZSK status
481*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 	Re-signing not necessary!
482*00b67f09SDavid van Moolenbroek2010-08-26 23:57:00.178: debug: 	Check if there is a parent file to copy
483*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 	Check RFC5011 status
484*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
485*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 	Check KSK status
486*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 	Check ZSK status
487*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 	Re-signing necessary: re-signing interval (2d) reached
488*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
489*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.546: debug: 	Writing key file "./example.net/dnskey.db"
490*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: 	Incrementing serial number in file "./example.net/zone.db"
491*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: 	Signing zone "example.net."
492*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.607: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9FC981 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
493*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.761: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
494*00b67f09SDavid van Moolenbroek2010-10-21 14:01:35.761: debug: 	Signing completed after 0s.
495*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 	Check RFC5011 status
496*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
497*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 	Check KSK status
498*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 	Check ZSK status
499*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 	Re-signing not necessary!
500*00b67f09SDavid van Moolenbroek2010-10-21 14:02:09.209: debug: 	Check if there is a parent file to copy
501*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 	Check RFC5011 status
502*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
503*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 	Check KSK status
504*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 	Check ZSK status
505*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 	Re-signing not necessary!
506*00b67f09SDavid van Moolenbroek2010-10-21 14:05:36.170: debug: 	Check if there is a parent file to copy
507*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 	Check RFC5011 status
508*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
509*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 	Check KSK status
510*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 	Check ZSK status
511*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 	Re-signing not necessary!
512*00b67f09SDavid van Moolenbroek2010-10-21 14:30:43.892: debug: 	Check if there is a parent file to copy
513*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 	Check RFC5011 status
514*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
515*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 	Check KSK status
516*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 	Check ZSK status
517*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 	Re-signing necessary: Modified keys
518*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: notice: "example.net.": re-signing triggered: Modified keys
519*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.729: debug: 	Writing key file "./example.net/dnskey.db"
520*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: 	Incrementing serial number in file "./example.net/zone.db"
521*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: 	Signing zone "example.net."
522*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.730: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 97195D -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
523*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.827: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
524*00b67f09SDavid van Moolenbroek2014-11-14 18:04:37.827: debug: 	Signing completed after 0s.
525*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: 	Check RFC5011 status
526*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
527*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.427: debug: 	Check KSK status
528*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.428: debug: 	No active KSK found: generate new one
529*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: info: "example.net.": generated new KSK 44671
530*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: debug: 	Check ZSK status
531*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.495: debug: 	No active ZSK found: generate new one
532*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.515: info: "example.net.": generated new ZSK 7929
533*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.515: debug: 	New key for pre-publishing needed
534*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: debug: 		->creating new key 2253
535*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: info: "example.net.": new key 2253 generated for pre-publishing
536*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: debug: 	Re-signing necessary: Modified zone key set
537*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.546: notice: "example.net.": re-signing triggered: Modified zone key set
538*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: 	Writing key file "./example.net/dnskey.db"
539*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: 	Incrementing serial number in file "./example.net/zone.db"
540*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: 	Signing zone "example.net."
541*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.547: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 B26BB7 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
542*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.646: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
543*00b67f09SDavid van Moolenbroek2014-11-14 18:09:16.646: debug: 	Signing completed after 0s.
544*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 	Check RFC5011 status
545*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
546*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 	Check KSK status
547*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 	Check ZSK status
548*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 	Re-signing not necessary!
549*00b67f09SDavid van Moolenbroek2014-11-14 18:11:40.877: debug: 	Check if there is a parent file to copy
550*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 	Check RFC5011 status
551*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
552*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 	Check KSK status
553*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 	Check ZSK status
554*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 	Re-signing not necessary!
555*00b67f09SDavid van Moolenbroek2014-11-14 18:11:46.599: debug: 	Check if there is a parent file to copy
556*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 	Check RFC5011 status
557*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
558*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 	Check KSK status
559*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 	Check ZSK status
560*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 	Re-signing not necessary!
561*00b67f09SDavid van Moolenbroek2014-11-14 18:15:54.380: debug: 	Check if there is a parent file to copy
562*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 	Check RFC5011 status
563*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
564*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 	Check KSK status
565*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 	Check ZSK status
566*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 	Re-signing necessary: Modified keys
567*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: notice: "example.net.": re-signing triggered: Modified keys
568*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.365: debug: 	Writing key file "././example.net/dnskey.db"
569*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: 	Incrementing serial number in file "././example.net/zone.db"
570*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: 	Signing zone "example.net."
571*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.366: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 8B4599 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
572*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.488: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
573*00b67f09SDavid van Moolenbroek2014-11-14 18:31:09.488: debug: 	Signing completed after 0s.
574*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 	Check RFC5011 status
575*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
576*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 	Check KSK status
577*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 	Check ZSK status
578*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 	Re-signing not necessary!
579*00b67f09SDavid van Moolenbroek2014-11-14 18:31:27.335: debug: 	Check if there is a parent file to copy
580*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Check RFC5011 status
581*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
582*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Check KSK status
583*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Check ZSK status
584*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Re-signing necessary: Modified keys
585*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: notice: "example.net.": re-signing triggered: Modified keys
586*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Writing key file "././example.net/dnskey.db"
587*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Incrementing serial number in file "././example.net/zone.db"
588*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	Signing zone "example.net."
589*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.356: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 BEBFB0 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
590*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.484: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
591*00b67f09SDavid van Moolenbroek2014-11-14 18:38:16.484: debug: 	Signing completed after 0s.
592*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: 	Check RFC5011 status
593*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
594*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: 	Check KSK status
595*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.572: debug: 	Check ZSK status
596*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: 	Re-signing necessary: Modified keys
597*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: notice: "example.net.": re-signing triggered: Modified keys
598*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: 	Writing key file "././example.net/dnskey.db"
599*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: 	Incrementing serial number in file "././example.net/zone.db"
600*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: 	Signing zone "example.net."
601*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.573: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 DC5680 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
602*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.715: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
603*00b67f09SDavid van Moolenbroek2014-11-15 18:16:50.715: debug: 	Signing completed after 0s.
604*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: 	Check RFC5011 status
605*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
606*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.202: debug: 	Check KSK status
607*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: 	Check ZSK status
608*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: 	Re-signing not necessary!
609*00b67f09SDavid van Moolenbroek2014-11-15 18:16:54.203: debug: 	Check if there is a parent file to copy
610*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Check RFC5011 status
611*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
612*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Check KSK status
613*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Check ZSK status
614*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Re-signing necessary: Modified keys
615*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: notice: "example.net.": re-signing triggered: Modified keys
616*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Writing key file "././example.net/dnskey.db"
617*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Incrementing serial number in file "././example.net/zone.db"
618*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	Signing zone "example.net."
619*00b67f09SDavid van Moolenbroek2014-11-15 18:17:06.919: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 D82F90 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
620*00b67f09SDavid van Moolenbroek2014-11-15 18:17:07.040: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
621*00b67f09SDavid van Moolenbroek2014-11-15 18:17:07.040: debug: 	Signing completed after 1s.
622*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: 	Check RFC5011 status
623*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
624*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.242: debug: 	Check KSK status
625*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	Check ZSK status
626*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	Re-signing necessary: Zone file edited
627*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: notice: "example.net.": re-signing triggered: Zone file edited
628*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	Writing key file "././example.net/dnskey.db"
629*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	Incrementing serial number in file "././example.net/zone.db"
630*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	Signing zone "example.net."
631*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.243: debug: 	  Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 603310 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
632*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.365: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
633*00b67f09SDavid van Moolenbroek2014-11-15 18:17:17.365: debug: 	Signing completed after 0s.
634*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 	Check RFC5011 status
635*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
636*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 	Check KSK status
637*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 	Check ZSK status
638*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 	Re-signing necessary: re-signing interval (2d) reached
639*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
640*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.250: debug: 	Writing key file "./example.net/dnskey.db"
641*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: 	Incrementing serial number in file "./example.net/zone.db"
642*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: 	Signing zone "example.net."
643*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.251: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9F5882 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
644*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.392: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
645*00b67f09SDavid van Moolenbroek2014-11-17 19:12:44.392: debug: 	Signing completed after 0s.
646*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 	Check RFC5011 status
647*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
648*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 	Check KSK status
649*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 	Check ZSK status
650*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 	Re-signing not necessary!
651*00b67f09SDavid van Moolenbroek2014-11-17 19:12:49.692: debug: 	Check if there is a parent file to copy
652*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 	Check RFC5011 status
653*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
654*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 	Check KSK status
655*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 	Check ZSK status
656*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 	Re-signing not necessary!
657*00b67f09SDavid van Moolenbroek2014-11-17 19:13:02.603: debug: 	Check if there is a parent file to copy
658*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Check RFC5011 status
659*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
660*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Check KSK status
661*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Check ZSK status
662*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Re-signing necessary: Modified keys
663*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: notice: "example.net.": re-signing triggered: Modified keys
664*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Writing key file "./example.net/dnskey.db"
665*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Incrementing serial number in file "./example.net/zone.db"
666*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.410: debug: 	Signing zone "example.net."
667*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.411: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 053453 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
668*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.525: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
669*00b67f09SDavid van Moolenbroek2014-11-17 19:13:50.525: debug: 	Signing completed after 0s.
670*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 	Check RFC5011 status
671*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
672*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 	Check KSK status
673*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 	Check ZSK status
674*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 	Re-signing not necessary!
675*00b67f09SDavid van Moolenbroek2014-11-17 19:13:54.302: debug: 	Check if there is a parent file to copy
676*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Check RFC5011 status
677*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
678*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Check KSK status
679*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Check ZSK status
680*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Re-signing necessary: Zone file edited
681*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: notice: "example.net.": re-signing triggered: Zone file edited
682*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Writing key file "./example.net/dnskey.db"
683*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Incrementing serial number in file "./example.net/zone.db"
684*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.846: debug: 	Signing zone "example.net."
685*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.847: debug: 	  Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 7CF530 -C -g -p -d ../keysets -o example.net. -e +518400  zone.db K*.private 2>&1"
686*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.969: debug: 	  Cmd dnssec-signzone return: "zone.db.signed"
687*00b67f09SDavid van Moolenbroek2014-11-17 19:14:01.969: debug: 	Signing completed after 0s.
688