Does NSD support ED25519 KSK/ZSK keys?

Vladimir Lomov <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
Hello,

the current ldns-keygen/ldns-signzone doesn't support ED25519/ED448
KSK/ZSK keys while dnssec-keygen can generate ED25519 keys. I generated
ED25519 KSK and ZSK keys using dnssec-keygen, published them in zone
file, checked the zone file (it is Ok) and sign zone by dnssec-signzone.
Though NSD was restarted successfully I wonder (actually I concern) does
NSD works fine with such keys?

I'm asking because I faced with strange problem with one of Registrar
(name.com) which supports ED25519/ED448 keys but their web interface
being able retrieve DNSKEY record from my DNS server unable to register
on their side the DS record for my DNS server.

Could it be that NSD couldn't work with ED25519 and sending wrong data
to Registrar when it tries to form DS record?

---
WBR, Vladimir Lomov

-- 
<Knghtbrd> you people are all insane.
<Joey> knight: sure, that's why we work on Debian.
<JHM> Knghtbrd: get in touch with your inner nutcase.

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYIAB0WIQQaopaKwcQWyz7yQfAHGfInzJc4BQUCXJmovAAKCRAHGfInzJc4
BZahAP4ucu5dzcKWsEcwHoldUUQYNDbs3RbSydWttul3QP4v2QEAkSrQwWaKDZEc
E7LcFAfEeJPvy7l6T+agMx/FGyYxbwQ=
=ieog
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.