Have you told named where the private keys are (key-directory)?
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: Mark_A...@isc.org
_______________________________________________
bind-users mailing list
bind-...@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users
Mar 19 11:53:23 new named[28753]: client 172.20.210.4#38722: view
default4: updating zone 'fred.com/IN': adding an RR at 'h2.fred.com' A
Mar 19 11:53:23 new named[28753]: client 172.20.210.4#38722: view
default4: updating zone 'fred.com/IN': RRSIG/NSEC update failed: sign
failure
The solution was to sign every dynamic zone with RSASHA1 keys only.
Alex
-----Original Message-----
From: bind-user...@lists.isc.org
[mailto:bind-user...@lists.isc.org] On Behalf Of Jack Tavares
Sent: Wednesday, May 13, 2009 4:03 AM
To: unlisted-recipients
Cc: bind-...@lists.isc.org
Subject: RE: error while attempting to use nsupdate on a DNSSEC signed
zone
yes.
And I when I previously failed to specify the correct key-directory, I
got an error
"found no private keys, unable to generate any signatures"
I corrected that error and now get the "failure" message
everything is owned by named .
options {
dnssec-enable yes;
dnssec-validation yes;
key-directory "/config/namedb";
--
Jack Tavares
________________________________________
From: Mark_A...@isc.org [Mark_A...@isc.org]
Sent: Wednesday, May 13, 2009 10:38
To: Jack Tavares
Cc: bind-...@lists.isc.org
Subject: Re: error while attempting to use nsupdate on a DNSSEC signed
zone
DSA requires a good random number generator to be available to
named. RSA only required a good random number generator at
key creation time.