Re: Bind 9.20 inline signing - not signing whole file, only dynamic updated entries.
Peter Davies <[email protected]> Fri, 17 Apr 2026 16:47:57 +0200
| Newsgroups | gmane.network.dns.bind.user |
|---|---|
| Message-ID | <[email protected]> |
Hi Benoît. Super, mystery solved. Thanks for sharing this with us. /Peter On 17/04/2026 15.51, Benoît Panizzon wrote: > 17-Apr-2026 15:44:45.348 dnssec: debug 3: keymgr: 0-31.57.161.157.in-addr.arpa done > 17-Apr-2026 15:44:45.348 dnssec: error: zone 0-31.57.161.157.in-addr.arpa/IN (signed): zone_rekey:dns_keymgr_run failed: error occurred writing key to disk > 17-Apr-2026 15:44:45.348 dnssec: error: zone 0-31.57.161.157.in-addr.arpa/IN (signed): zone_rekey failure: error occurred writing key to disk (retry in 600 seconds) > > Ok - permissions! > > Wow, how could I miss /etc/bind/keys belonging to root:bind with group permissions s-x > > Keyfiles present. > > name: 0-31.57.161.157.in-addr.arpa > type: primary > files: woody.ch.rev > serial: 2007126016 > signed serial: 2007126025 > nodes: 31 > last loaded: Fri, 17 Apr 2026 09:04:20 GMT > secure: yes > inline signing: yes > key maintenance: automatic > next key event: Fri, 17 Apr 2026 15:52:43 GMT > next resign node: 20.0-31.57.161.157.in-addr.arpa/NSEC > next resign time: Sun, 26 Apr 2026 04:20:25 GMT > dynamic: yes > frozen: no > reconfigurable via modzone: no > > secondary has loaded signed enries. > > Thanks for your help and sorry that I missed something that obvious. > -- Peter Davies Support Engineer Internet Systems Corporation [email protected] 001 650-423-1460 -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.