1 2010-02-06 00:26:54.533: debug: Check RFC5011 status
2 2010-02-06 00:26:54.533: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
3 2010-02-06 00:26:54.533: debug: Check KSK status
4 2010-02-06 00:26:54.533: debug: Check ZSK status
5 2010-02-06 00:26:54.533: debug: Re-signing not necessary!
6 2010-02-06 00:26:54.533: debug: Check if there is a parent file to copy
7 2010-02-06 00:29:31.291: debug: Check RFC5011 status
8 2010-02-06 00:29:31.291: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
9 2010-02-06 00:29:31.291: debug: Check KSK status
10 2010-02-06 00:29:31.292: debug: Check ZSK status
11 2010-02-06 00:29:31.292: debug: Re-signing not necessary!
12 2010-02-06 00:29:31.292: debug: Check if there is a parent file to copy
13 2010-02-06 00:40:35.043: debug: Check RFC5011 status
14 2010-02-06 00:40:35.043: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
15 2010-02-06 00:40:35.043: debug: Check KSK status
16 2010-02-06 00:40:35.043: debug: Check ZSK status
17 2010-02-06 00:40:35.043: debug: Re-signing not necessary!
18 2010-02-06 00:40:35.043: debug: Check if there is a parent file to copy
19 2010-02-06 00:52:55.403: debug: Check RFC5011 status
20 2010-02-06 00:52:55.403: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
21 2010-02-06 00:52:55.403: debug: Check KSK status
22 2010-02-06 00:52:55.403: debug: Check ZSK status
23 2010-02-06 00:52:55.403: debug: Re-signing not necessary!
24 2010-02-06 00:52:55.403: debug: Check if there is a parent file to copy
25 2010-02-07 13:53:48.304: debug: Check RFC5011 status
26 2010-02-07 13:53:48.304: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
27 2010-02-07 13:53:48.304: debug: Check KSK status
28 2010-02-07 13:53:48.304: debug: Check ZSK status
29 2010-02-07 13:53:48.304: debug: Re-signing not necessary!
30 2010-02-07 13:53:48.304: debug: Check if there is a parent file to copy
31 2010-02-07 13:54:03.466: debug: Check RFC5011 status
32 2010-02-07 13:54:03.466: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
33 2010-02-07 13:54:03.466: debug: Check KSK status
34 2010-02-07 13:54:03.466: debug: Check ZSK status
35 2010-02-07 13:54:03.466: debug: Re-signing not necessary!
36 2010-02-07 13:54:03.466: debug: Check if there is a parent file to copy
37 2010-02-07 13:54:08.019: debug: Check RFC5011 status
38 2010-02-07 13:54:08.019: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
39 2010-02-07 13:54:08.020: debug: Check KSK status
40 2010-02-07 13:54:08.020: debug: Check ZSK status
41 2010-02-07 13:54:08.020: debug: Re-signing necessary: Option -f
42 2010-02-07 13:54:08.020: notice: "example.net.": re-signing triggered: Option -f
43 2010-02-07 13:54:08.020: debug: Writing key file "./example.net/dnskey.db"
44 2010-02-07 13:54:08.020: debug: Incrementing serial number in file "./example.net/zone.db"
45 2010-02-07 13:54:08.020: debug: Signing zone "example.net."
46 2010-02-07 13:54:08.021: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
47 2010-02-07 13:54:08.125: debug: Cmd dnssec-signzone return: "zone.db.signed"
48 2010-02-07 13:54:08.125: debug: Signing completed after 0s.
49 2010-02-07 13:54:08.125: notice: "example.net.": distribution triggered
50 2010-02-07 13:54:08.125: debug: Distribute zone "example.net."
51 2010-02-07 13:54:08.125: debug: Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed "
52 2010-02-07 13:54:08.129: debug: ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./"
53 2010-02-07 13:54:08.129: notice: "example.net.": reload triggered
54 2010-02-07 13:54:08.129: debug: Reload zone "example.net."
55 2010-02-07 13:54:08.129: debug: Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed "
56 2010-02-07 13:54:08.139: debug: ./dist.sh reload return: "rndc reload example.net. "
57 2010-02-07 14:06:27.670: debug: Check RFC5011 status
58 2010-02-07 14:06:27.670: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
59 2010-02-07 14:06:27.670: debug: Check KSK status
60 2010-02-07 14:06:27.670: debug: Check ZSK status
61 2010-02-07 14:06:27.670: debug: Re-signing not necessary!
62 2010-02-07 14:06:27.671: debug: Check if there is a parent file to copy
63 2010-02-07 14:06:33.753: debug: Check RFC5011 status
64 2010-02-07 14:06:33.753: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
65 2010-02-07 14:06:33.753: debug: Check KSK status
66 2010-02-07 14:06:33.753: debug: Check ZSK status
67 2010-02-07 14:06:33.753: debug: Re-signing necessary: Option -f
68 2010-02-07 14:06:33.753: notice: "example.net.": re-signing triggered: Option -f
69 2010-02-07 14:06:33.753: debug: Writing key file "./example.net/dnskey.db"
70 2010-02-07 14:06:33.754: debug: Incrementing serial number in file "./example.net/zone.db"
71 2010-02-07 14:06:33.754: debug: Signing zone "example.net."
72 2010-02-07 14:06:33.754: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
73 2010-02-07 14:06:33.790: debug: Cmd dnssec-signzone return: "zone.db.signed"
74 2010-02-07 14:06:33.790: debug: Signing completed after 0s.
75 2010-02-07 14:06:33.790: notice: "example.net.": distribution triggered
76 2010-02-07 14:06:33.790: debug: Distribute zone "example.net."
77 2010-02-07 14:06:33.790: debug: Run cmd "./dist.sh distribute example.net. ./example.net/zone.db.signed "
78 2010-02-07 14:06:33.794: debug: ./dist.sh distribute return: "scp ./example.net/zone.db.signed localhost:/var/named/example.net./"
79 2010-02-07 14:06:33.794: notice: "example.net.": reload triggered
80 2010-02-07 14:06:33.794: debug: Reload zone "example.net."
81 2010-02-07 14:06:33.794: debug: Run cmd "./dist.sh reload example.net. ./example.net/zone.db.signed "
82 2010-02-07 14:06:33.797: debug: ./dist.sh reload return: "rndc reload example.net. "
83 2010-02-21 12:50:43.587: debug: Check RFC5011 status
84 2010-02-21 12:50:43.587: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
85 2010-02-21 12:50:43.587: debug: Check KSK status
86 2010-02-21 12:50:43.587: debug: Check ZSK status
87 2010-02-21 12:50:43.587: debug: Lifetime(1209600 +/-150 sec) of active key 33002 exceeded (2394625 sec)
88 2010-02-21 12:50:43.587: debug: ->depreciate it
89 2010-02-21 12:50:43.587: debug: ->activate published key 29240
90 2010-02-21 12:50:43.587: notice: "example.net.": lifetime of zone signing key 33002 exceeded: ZSK rollover done
91 2010-02-21 12:50:43.587: debug: New key for publishing needed
92 2010-02-21 12:50:43.658: debug: ->creating new key 5525
93 2010-02-21 12:50:43.658: info: "example.net.": new key 5525 generated for publishing
94 2010-02-21 12:50:43.658: debug: Re-signing necessary: Modfied zone key set
95 2010-02-21 12:50:43.658: notice: "example.net.": re-signing triggered: Modfied zone key set
96 2010-02-21 12:50:43.658: debug: Writing key file "./example.net/dnskey.db"
97 2010-02-21 12:50:43.665: debug: Incrementing serial number in file "./example.net/zone.db"
98 2010-02-21 12:50:43.665: debug: Signing zone "example.net."
99 2010-02-21 12:50:43.665: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
100 2010-02-21 12:50:43.733: debug: Cmd dnssec-signzone return: "zone.db.signed"
101 2010-02-21 12:50:43.733: debug: Signing completed after 0s.
102 2010-02-21 12:50:51.205: debug: Check RFC5011 status
103 2010-02-21 12:50:51.205: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
104 2010-02-21 12:50:51.205: debug: Check KSK status
105 2010-02-21 12:50:51.205: debug: Check ZSK status
106 2010-02-21 12:50:51.205: debug: Re-signing not necessary!
107 2010-02-21 12:50:51.205: debug: Check if there is a parent file to copy
108 2010-02-21 12:51:23.497: debug: Check RFC5011 status
109 2010-02-21 12:51:23.497: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
110 2010-02-21 12:51:23.497: debug: Check KSK status
111 2010-02-21 12:51:23.497: debug: Check ZSK status
112 2010-02-21 12:51:23.497: debug: Re-signing not necessary!
113 2010-02-21 12:51:23.497: debug: Check if there is a parent file to copy
114 2010-02-21 19:16:18.594: debug: Check RFC5011 status
115 2010-02-21 19:16:18.594: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
116 2010-02-21 19:16:18.594: debug: Check KSK status
117 2010-02-21 19:16:18.594: debug: Check ZSK status
118 2010-02-21 19:16:18.594: debug: Re-signing not necessary!
119 2010-02-21 19:16:18.594: debug: Check if there is a parent file to copy
120 2010-02-21 19:32:11.378: debug: Check RFC5011 status
121 2010-02-21 19:32:11.378: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
122 2010-02-21 19:32:11.378: debug: Check KSK status
123 2010-02-21 19:32:11.378: debug: Check ZSK status
124 2010-02-21 19:32:11.378: debug: Re-signing not necessary!
125 2010-02-21 19:32:11.378: debug: Check if there is a parent file to copy
126 2010-02-21 19:32:15.982: debug: Check RFC5011 status
127 2010-02-21 19:32:15.982: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
128 2010-02-21 19:32:15.982: debug: Check KSK status
129 2010-02-21 19:32:15.982: debug: Check ZSK status
130 2010-02-21 19:32:15.982: debug: Re-signing necessary: Option -f
131 2010-02-21 19:32:15.982: notice: "example.net.": re-signing triggered: Option -f
132 2010-02-21 19:32:15.982: debug: Writing key file "./example.net/dnskey.db"
133 2010-02-21 19:32:15.982: debug: Incrementing serial number in file "./example.net/zone.db"
134 2010-02-21 19:32:15.982: debug: Signing zone "example.net."
135 2010-02-21 19:32:15.982: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
136 2010-02-21 19:32:16.019: debug: Cmd dnssec-signzone return: "zone.db.signed"
137 2010-02-21 19:32:16.019: debug: Signing completed after 1s.
138 2010-02-21 19:32:32.232: debug: Check RFC5011 status
139 2010-02-21 19:32:32.232: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
140 2010-02-21 19:32:32.233: debug: Check KSK status
141 2010-02-21 19:32:32.233: debug: Check ZSK status
142 2010-02-21 19:32:32.233: debug: Re-signing necessary: Option -f
143 2010-02-21 19:32:32.233: notice: "example.net.": re-signing triggered: Option -f
144 2010-02-21 19:32:32.233: debug: Writing key file "./example.net/dnskey.db"
145 2010-02-21 19:32:32.233: debug: Incrementing serial number in file "./example.net/zone.db"
146 2010-02-21 19:32:32.233: debug: Signing zone "example.net."
147 2010-02-21 19:32:32.233: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
148 2010-02-21 19:32:32.273: debug: Cmd dnssec-signzone return: "zone.db.signed"
149 2010-02-21 19:32:32.273: debug: Signing completed after 0s.
150 2010-02-25 00:12:27.060: debug: Check RFC5011 status
151 2010-02-25 00:12:27.060: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
152 2010-02-25 00:12:27.060: debug: Check KSK status
153 2010-02-25 00:12:27.060: debug: Check ZSK status
154 2010-02-25 00:12:27.060: debug: Lifetime(29100 sec) of depreciated key 33002 exceeded (300104 sec)
155 2010-02-25 00:12:27.060: info: "example.net.": old ZSK 33002 removed
156 2010-02-25 00:12:27.081: debug: ->remove it
157 2010-02-25 00:12:27.082: debug: Re-signing necessary: Modfied zone key set
158 2010-02-25 00:12:27.082: notice: "example.net.": re-signing triggered: Modfied zone key set
159 2010-02-25 00:12:27.082: debug: Writing key file "./example.net/dnskey.db"
160 2010-02-25 00:12:27.086: debug: Incrementing serial number in file "./example.net/zone.db"
161 2010-02-25 00:12:27.086: debug: Signing zone "example.net."
162 2010-02-25 00:12:27.086: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
163 2010-02-25 00:12:27.173: debug: Cmd dnssec-signzone return: "zone.db.signed"
164 2010-02-25 00:12:27.174: debug: Signing completed after 0s.
165 2010-02-25 23:42:21.013: debug: Check RFC5011 status
166 2010-02-25 23:42:21.013: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
167 2010-02-25 23:42:21.013: debug: Check KSK status
168 2010-02-25 23:42:21.013: debug: Check ZSK status
169 2010-02-25 23:42:21.013: debug: Re-signing not necessary!
170 2010-02-25 23:42:21.013: debug: Check if there is a parent file to copy
171 2010-03-02 10:59:12.416: debug: Check RFC5011 status
172 2010-03-02 10:59:12.416: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
173 2010-03-02 10:59:12.416: debug: Check KSK status
174 2010-03-02 10:59:12.416: debug: Check ZSK status
175 2010-03-02 10:59:12.416: debug: Re-signing necessary: re-signing interval (2d) reached
176 2010-03-02 10:59:12.416: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
177 2010-03-02 10:59:12.416: debug: Writing key file "./example.net/dnskey.db"
178 2010-03-02 10:59:12.449: debug: Incrementing serial number in file "./example.net/zone.db"
179 2010-03-02 10:59:12.449: debug: Signing zone "example.net."
180 2010-03-02 10:59:12.450: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
181 2010-03-02 10:59:12.530: debug: Cmd dnssec-signzone return: "zone.db.signed"
182 2010-03-02 10:59:12.530: debug: Signing completed after 0s.
183 2010-03-03 23:22:00.415: debug: Check RFC5011 status
184 2010-03-03 23:22:00.415: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
185 2010-03-03 23:22:00.415: debug: Check KSK status
186 2010-03-03 23:22:00.415: debug: Check ZSK status
187 2010-03-03 23:22:00.416: debug: Re-signing not necessary!
188 2010-03-03 23:22:00.416: debug: Check if there is a parent file to copy
189 2010-03-08 23:11:50.170: debug: Check RFC5011 status
190 2010-03-08 23:11:50.170: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
191 2010-03-08 23:11:50.170: debug: Check KSK status
192 2010-03-08 23:11:50.170: debug: Check ZSK status
193 2010-03-08 23:11:50.171: debug: Lifetime(1209600 +/-150 sec) of active key 29240 exceeded (1333267 sec)
194 2010-03-08 23:11:50.171: debug: ->depreciate it
195 2010-03-08 23:11:50.171: debug: ->activate published key 5525
196 2010-03-08 23:11:50.171: notice: "example.net.": lifetime of zone signing key 29240 exceeded: ZSK rollover done
197 2010-03-08 23:11:50.171: debug: New key for publishing needed
198 2010-03-08 23:11:50.228: debug: ->creating new key 21482
199 2010-03-08 23:11:50.228: info: "example.net.": new key 21482 generated for publishing
200 2010-03-08 23:11:50.228: debug: Re-signing necessary: Modfied zone key set
201 2010-03-08 23:11:50.228: notice: "example.net.": re-signing triggered: Modfied zone key set
202 2010-03-08 23:11:50.228: debug: Writing key file "././example.net/dnskey.db"
203 2010-03-08 23:11:50.235: debug: Incrementing serial number in file "././example.net/zone.db"
204 2010-03-08 23:11:50.235: debug: Signing zone "example.net."
205 2010-03-08 23:11:50.235: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
206 2010-03-08 23:11:50.294: debug: Cmd dnssec-signzone return: "zone.db.signed"
207 2010-03-08 23:11:50.294: debug: Signing completed after 0s.
208 2010-03-08 23:12:56.212: debug: Check RFC5011 status
209 2010-03-08 23:12:56.212: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
210 2010-03-08 23:12:56.212: debug: Check KSK status
211 2010-03-08 23:12:56.212: debug: Check ZSK status
212 2010-03-08 23:12:56.212: debug: Re-signing necessary: Modfied zone key set
213 2010-03-08 23:12:56.212: notice: "example.net.": re-signing triggered: Modfied zone key set
214 2010-03-08 23:12:56.212: debug: Writing key file "././example.net/dnskey.db"
215 2010-03-08 23:12:56.213: debug: Incrementing serial number in file "././example.net/zone.db"
216 2010-03-08 23:12:56.213: debug: Signing zone "example.net."
217 2010-03-08 23:12:56.213: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
218 2010-03-08 23:12:56.278: debug: Cmd dnssec-signzone return: "zone.db.signed"
219 2010-03-08 23:12:56.279: debug: Signing completed after 0s.
220 2010-03-08 23:13:36.984: debug: Check RFC5011 status
221 2010-03-08 23:13:36.984: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
222 2010-03-08 23:13:36.984: debug: Check KSK status
223 2010-03-08 23:13:36.984: debug: Check ZSK status
224 2010-03-08 23:13:36.985: debug: Re-signing not necessary!
225 2010-03-08 23:13:36.985: debug: Check if there is a parent file to copy
226 2010-03-08 23:18:52.287: debug: Check RFC5011 status
227 2010-03-08 23:18:52.287: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
228 2010-03-08 23:18:52.287: debug: Check KSK status
229 2010-03-08 23:18:52.287: debug: Check ZSK status
230 2010-03-08 23:18:52.287: debug: Re-signing not necessary!
231 2010-03-08 23:18:52.287: debug: Check if there is a parent file to copy
232 2010-03-11 23:46:35.831: debug: Check RFC5011 status
233 2010-03-11 23:46:35.831: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
234 2010-03-11 23:46:35.831: debug: Check KSK status
235 2010-03-11 23:46:35.831: debug: Check ZSK status
236 2010-03-11 23:46:35.831: debug: Lifetime(29100 sec) of depreciated key 29240 exceeded (261285 sec)
237 2010-03-11 23:46:35.831: info: "example.net.": old ZSK 29240 removed
238 2010-03-11 23:46:35.832: debug: ->remove it
239 2010-03-11 23:46:35.832: debug: Re-signing necessary: Modfied zone key set
240 2010-03-11 23:46:35.832: notice: "example.net.": re-signing triggered: Modfied zone key set
241 2010-03-11 23:46:35.832: debug: Writing key file "./example.net/dnskey.db"
242 2010-03-11 23:46:35.841: debug: Incrementing serial number in file "./example.net/zone.db"
243 2010-03-11 23:46:35.841: debug: Signing zone "example.net."
244 2010-03-11 23:46:35.841: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
245 2010-03-11 23:46:35.929: debug: Cmd dnssec-signzone return: "zone.db.signed"
246 2010-03-11 23:46:35.929: debug: Signing completed after 0s.
247 2010-03-11 23:52:33.132: debug: Check RFC5011 status
248 2010-03-11 23:52:33.132: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
249 2010-03-11 23:52:33.133: debug: Check KSK status
250 2010-03-11 23:52:33.133: debug: No active KSK found: generate new one
251 2010-03-11 23:52:33.374: info: "example.net.": generated new KSK 8406
252 2010-03-11 23:52:33.374: debug: Check ZSK status
253 2010-03-11 23:52:33.374: debug: No active ZSK found: generate new one
254 2010-03-11 23:52:33.400: info: "example.net.": generated new ZSK 36257
255 2010-03-11 23:52:33.400: debug: Re-signing necessary: Modfied zone key set
256 2010-03-11 23:52:33.400: notice: "example.net.": re-signing triggered: Modfied zone key set
257 2010-03-11 23:52:33.400: debug: Writing key file "./example.net/dnskey.db"
258 2010-03-11 23:52:33.400: debug: Incrementing serial number in file "./example.net/zone.db"
259 2010-03-11 23:52:33.400: debug: Signing zone "example.net."
260 2010-03-11 23:52:33.400: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 69AE05 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
261 2010-03-11 23:52:33.408: debug: Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 generation requested with NSEC only DNSKEY"
262 2010-03-11 23:52:33.408: error: "example.net.": signing failed!
263 2010-03-11 23:53:27.856: debug: Check RFC5011 status
264 2010-03-11 23:53:27.856: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
265 2010-03-11 23:53:27.856: debug: Check KSK status
266 2010-03-11 23:53:27.856: debug: Check ZSK status
267 2010-03-11 23:53:27.856: debug: Re-signing necessary: Modified keys
268 2010-03-11 23:53:27.856: notice: "example.net.": re-signing triggered: Modified keys
269 2010-03-11 23:53:27.856: debug: Writing key file "./example.net/dnskey.db"
270 2010-03-11 23:53:27.856: debug: Incrementing serial number in file "./example.net/zone.db"
271 2010-03-11 23:53:27.856: debug: Signing zone "example.net."
272 2010-03-11 23:53:27.856: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 67AA7F -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
273 2010-03-11 23:53:27.920: debug: Cmd dnssec-signzone return: "zone.db.signed"
274 2010-03-11 23:53:27.920: debug: Signing completed after 0s.
275 2010-07-05 08:15:24.179: debug: Check RFC5011 status
276 2010-07-05 08:15:24.179: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
277 2010-07-05 08:15:24.179: debug: Check KSK status
278 2010-07-05 08:15:24.179: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m44s
279 2010-07-05 08:15:24.179: debug: Check ZSK status
280 2010-07-05 08:15:24.179: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081384 sec)
281 2010-07-05 08:15:24.179: debug: ->waiting for published key
282 2010-07-05 08:15:24.179: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m44s: ZSK rollover deferred: waiting for published key
283 2010-07-05 08:15:24.179: debug: New key for publishing needed
284 2010-07-05 08:15:24.278: debug: ->creating new key 48476
285 2010-07-05 08:15:24.278: info: "example.net.": new key 48476 generated for publishing
286 2010-07-05 08:15:24.278: debug: Re-signing necessary: Modfied zone key set
287 2010-07-05 08:15:24.278: notice: "example.net.": re-signing triggered: Modfied zone key set
288 2010-07-05 08:15:24.278: debug: Writing key file "./example.net/dnskey.db"
289 2010-07-05 08:15:24.278: debug: Incrementing serial number in file "./example.net/zone.db"
290 2010-07-05 08:15:24.278: debug: Signing zone "example.net."
291 2010-07-05 08:15:24.278: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5816F0 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
292 2010-07-05 08:15:24.315: debug: Cmd dnssec-signzone return: "zone.db.signed"
293 2010-07-05 08:15:24.315: debug: Signing completed after 0s.
294 2010-07-05 08:15:28.174: debug: Check RFC5011 status
295 2010-07-05 08:15:28.174: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
296 2010-07-05 08:15:28.174: debug: Check KSK status
297 2010-07-05 08:15:28.174: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h49m48s
298 2010-07-05 08:15:28.174: debug: Check ZSK status
299 2010-07-05 08:15:28.174: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081388 sec)
300 2010-07-05 08:15:28.174: debug: ->waiting for published key
301 2010-07-05 08:15:28.174: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h49m48s: ZSK rollover deferred: waiting for published key
302 2010-07-05 08:15:28.174: debug: Re-signing not necessary!
303 2010-07-05 08:15:28.174: debug: Check if there is a parent file to copy
304 2010-07-05 08:15:58.502: debug: Check RFC5011 status
305 2010-07-05 08:15:58.502: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
306 2010-07-05 08:15:58.503: debug: Check KSK status
307 2010-07-05 08:15:58.503: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m18s
308 2010-07-05 08:15:58.503: debug: Check ZSK status
309 2010-07-05 08:15:58.503: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081418 sec)
310 2010-07-05 08:15:58.503: debug: ->waiting for published key
311 2010-07-05 08:15:58.503: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m18s: ZSK rollover deferred: waiting for published key
312 2010-07-05 08:15:58.503: debug: Re-signing not necessary!
313 2010-07-05 08:15:58.503: debug: Check if there is a parent file to copy
314 2010-07-05 08:16:04.937: debug: Check RFC5011 status
315 2010-07-05 08:16:04.937: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
316 2010-07-05 08:16:04.937: debug: Check KSK status
317 2010-07-05 08:16:04.937: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m24s
318 2010-07-05 08:16:04.937: debug: Check ZSK status
319 2010-07-05 08:16:04.937: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081424 sec)
320 2010-07-05 08:16:04.937: debug: ->waiting for published key
321 2010-07-05 08:16:04.937: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m24s: ZSK rollover deferred: waiting for published key
322 2010-07-05 08:16:04.937: debug: Re-signing necessary: Option -f
323 2010-07-05 08:16:04.937: notice: "example.net.": re-signing triggered: Option -f
324 2010-07-05 08:16:04.937: debug: Writing key file "./example.net/dnskey.db"
325 2010-07-05 08:16:04.937: debug: Incrementing serial number in file "./example.net/zone.db"
326 2010-07-05 08:16:04.937: debug: Signing zone "example.net."
327 2010-07-05 08:16:04.937: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 C58544 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
328 2010-07-05 08:16:04.993: debug: Cmd dnssec-signzone return: "zone.db.signed"
329 2010-07-05 08:16:04.993: debug: Signing completed after 0s.
330 2010-07-05 08:16:33.604: debug: Check RFC5011 status
331 2010-07-05 08:16:33.604: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
332 2010-07-05 08:16:33.604: debug: Check KSK status
333 2010-07-05 08:16:33.604: warning: "example.net.": lifetime of key signing key 8406 exceeded since 4w5d12h50m53s
334 2010-07-05 08:16:33.604: debug: Check ZSK status
335 2010-07-05 08:16:33.604: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (8081453 sec)
336 2010-07-05 08:16:33.604: debug: ->waiting for published key
337 2010-07-05 08:16:33.604: notice: "example.net.": lifetime of zone signing key 36257 exceeded since 11w2d12h50m53s: ZSK rollover deferred: waiting for published key
338 2010-07-05 08:16:33.604: debug: Re-signing necessary: Option -f
339 2010-07-05 08:16:33.604: notice: "example.net.": re-signing triggered: Option -f
340 2010-07-05 08:16:33.604: debug: Writing key file "./example.net/dnskey.db"
341 2010-07-05 08:16:33.605: debug: Incrementing serial number in file "./example.net/zone.db"
342 2010-07-05 08:16:33.605: debug: Signing zone "example.net."
343 2010-07-05 08:16:33.605: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 FCB8E2 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
344 2010-07-05 08:16:33.648: debug: Cmd dnssec-signzone return: "zone.db.signed"
345 2010-07-05 08:16:33.648: debug: Signing completed after 0s.
346 2010-07-30 01:30:55.411: debug: Check RFC5011 status
347 2010-07-30 01:30:55.411: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
348 2010-07-30 01:30:55.411: debug: Check KSK status
349 2010-07-30 01:30:55.411: debug: Check ZSK status
350 2010-07-30 01:30:55.411: debug: Lifetime(1209600 +/-150 sec) of active key 36257 exceeded (2130473 sec)
351 2010-07-30 01:30:55.411: debug: ->depreciate it
352 2010-07-30 01:30:55.411: debug: ->activate published key 48476
353 2010-07-30 01:30:55.411: notice: "example.net.": lifetime of zone signing key 36257 exceeded: ZSK rollover done
354 2010-07-30 01:30:55.411: debug: New key for publishing needed
355 2010-07-30 01:30:55.493: debug: ->creating new key 1775
356 2010-07-30 01:30:55.493: info: "example.net.": new key 1775 generated for publishing
357 2010-07-30 01:30:55.493: debug: Re-signing necessary: Modfied zone key set
358 2010-07-30 01:30:55.493: notice: "example.net.": re-signing triggered: Modfied zone key set
359 2010-07-30 01:30:55.493: debug: Writing key file "./example.net/dnskey.db"
360 2010-07-30 01:30:55.493: debug: Incrementing serial number in file "./example.net/zone.db"
361 2010-07-30 01:30:55.493: debug: Signing zone "example.net."
362 2010-07-30 01:30:55.494: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 3723BA -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
363 2010-07-30 01:30:55.563: debug: Cmd dnssec-signzone return: "zone.db.signed"
364 2010-07-30 01:30:55.563: debug: Signing completed after 0s.
365 2010-08-26 22:52:09.539: debug: Check RFC5011 status
366 2010-08-26 22:52:09.539: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
367 2010-08-26 22:52:09.539: debug: Check KSK status
368 2010-08-26 22:52:09.539: debug: Check ZSK status
369 2010-08-26 22:52:09.539: debug: Lifetime(29100 sec) of depreciated key 36257 exceeded (2409674 sec)
370 2010-08-26 22:52:09.539: info: "example.net.": old ZSK 36257 removed
371 2010-08-26 22:52:09.572: debug: ->remove it
372 2010-08-26 22:52:09.572: debug: Lifetime(1209600 +/-150 sec) of active key 48476 exceeded (2409674 sec)
373 2010-08-26 22:52:09.572: debug: ->depreciate it
374 2010-08-26 22:52:09.572: debug: ->activate published key 1775
375 2010-08-26 22:52:09.572: notice: "example.net.": lifetime of zone signing key 48476 exceeded: ZSK rollover done
376 2010-08-26 22:52:09.572: debug: New key for publishing needed
377 2010-08-26 22:52:09.640: debug: ->creating new key 26477
378 2010-08-26 22:52:09.640: info: "example.net.": new key 26477 generated for publishing
379 2010-08-26 22:52:09.640: debug: Re-signing necessary: Modfied zone key set
380 2010-08-26 22:52:09.640: notice: "example.net.": re-signing triggered: Modfied zone key set
381 2010-08-26 22:52:09.640: debug: Writing key file "./example.net/dnskey.db"
382 2010-08-26 22:52:09.641: debug: Incrementing serial number in file "./example.net/zone.db"
383 2010-08-26 22:52:09.641: debug: Signing zone "example.net."
384 2010-08-26 22:52:09.641: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 2F41F9 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
385 2010-08-26 22:52:09.704: debug: Cmd dnssec-signzone return: "zone.db.signed"
386 2010-08-26 22:52:09.704: debug: Signing completed after 0s.
387 2010-08-26 22:56:02.938: debug: Check RFC5011 status
388 2010-08-26 22:56:02.938: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
389 2010-08-26 22:56:02.938: debug: Check KSK status
390 2010-08-26 22:56:02.938: debug: Check ZSK status
391 2010-08-26 22:56:02.938: debug: Re-signing not necessary!
392 2010-08-26 22:56:02.938: debug: Check if there is a parent file to copy
393 2010-08-26 23:06:00.593: debug: Check RFC5011 status
394 2010-08-26 23:06:00.593: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
395 2010-08-26 23:06:00.593: debug: Check KSK status
396 2010-08-26 23:06:00.593: debug: Check ZSK status
397 2010-08-26 23:06:00.593: debug: New key for publishing needed
398 2010-08-26 23:06:00.631: debug: ->creating new key 18026
399 2010-08-26 23:06:00.631: info: "example.net.": new key 18026 generated for publishing
400 2010-08-26 23:06:00.631: debug: Re-signing necessary: Modfied zone key set
401 2010-08-26 23:06:00.631: notice: "example.net.": re-signing triggered: Modfied zone key set
402 2010-08-26 23:06:00.631: debug: Writing key file "./example.net/dnskey.db"
403 2010-08-26 23:06:00.631: debug: Incrementing serial number in file "./example.net/zone.db"
404 2010-08-26 23:06:00.631: debug: Signing zone "example.net."
405 2010-08-26 23:06:00.631: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 5EA89E -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
406 2010-08-26 23:06:00.672: debug: Cmd dnssec-signzone return: "zone.db.signed"
407 2010-08-26 23:06:00.672: debug: Signing completed after 0s.
408 2010-08-26 23:11:33.808: debug: Check RFC5011 status
409 2010-08-26 23:11:33.808: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
410 2010-08-26 23:11:33.809: debug: Check KSK status
411 2010-08-26 23:11:33.809: debug: Check ZSK status
412 2010-08-26 23:11:33.809: debug: Re-signing not necessary!
413 2010-08-26 23:11:33.809: debug: Check if there is a parent file to copy
414 2010-08-26 23:12:51.012: debug: Check RFC5011 status
415 2010-08-26 23:12:51.012: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
416 2010-08-26 23:12:51.012: debug: Check KSK status
417 2010-08-26 23:12:51.012: debug: Check ZSK status
418 2010-08-26 23:12:51.012: debug: Re-signing not necessary!
419 2010-08-26 23:12:51.012: debug: Check if there is a parent file to copy
420 2010-08-26 23:23:47.886: debug: Check RFC5011 status
421 2010-08-26 23:23:47.886: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
422 2010-08-26 23:23:47.886: debug: Check KSK status
423 2010-08-26 23:23:47.886: debug: Check ZSK status
424 2010-08-26 23:23:47.886: debug: Re-signing not necessary!
425 2010-08-26 23:23:47.886: debug: Check if there is a parent file to copy
426 2010-08-26 23:50:15.724: debug: Check RFC5011 status
427 2010-08-26 23:50:15.724: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
428 2010-08-26 23:50:15.724: debug: Check KSK status
429 2010-08-26 23:50:15.724: debug: Check ZSK status
430 2010-08-26 23:50:15.725: debug: Re-signing not necessary!
431 2010-08-26 23:50:15.725: debug: Check if there is a parent file to copy
432 2010-08-26 23:50:55.124: debug: Check RFC5011 status
433 2010-08-26 23:50:55.124: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
434 2010-08-26 23:50:55.124: debug: Check KSK status
435 2010-08-26 23:50:55.124: debug: Check ZSK status
436 2010-08-26 23:50:55.124: debug: Re-signing not necessary!
437 2010-08-26 23:50:55.124: debug: Check if there is a parent file to copy
438 2010-08-26 23:51:46.719: debug: Check RFC5011 status
439 2010-08-26 23:51:46.719: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
440 2010-08-26 23:51:46.719: debug: Check KSK status
441 2010-08-26 23:51:46.719: debug: Check ZSK status
442 2010-08-26 23:51:46.719: debug: Re-signing not necessary!
443 2010-08-26 23:51:46.719: debug: Check if there is a parent file to copy
444 2010-08-26 23:54:22.824: debug: Check RFC5011 status
445 2010-08-26 23:54:22.824: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
446 2010-08-26 23:54:22.824: debug: Check KSK status
447 2010-08-26 23:54:22.824: debug: Check ZSK status
448 2010-08-26 23:54:22.824: debug: Re-signing not necessary!
449 2010-08-26 23:54:22.825: debug: Check if there is a parent file to copy
450 2010-08-26 23:55:00.018: debug: Check RFC5011 status
451 2010-08-26 23:55:00.018: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
452 2010-08-26 23:55:00.018: debug: Check KSK status
453 2010-08-26 23:55:00.018: debug: Check ZSK status
454 2010-08-26 23:55:00.018: debug: New key for pre-publishing needed
455 2010-08-26 23:55:00.110: debug: ->creating new key 18293
456 2010-08-26 23:55:00.110: info: "example.net.": new key 18293 generated for pre-publishing
457 2010-08-26 23:55:00.110: debug: Re-signing necessary: Modfied zone key set
458 2010-08-26 23:55:00.110: notice: "example.net.": re-signing triggered: Modfied zone key set
459 2010-08-26 23:55:00.110: debug: Writing key file "./example.net/dnskey.db"
460 2010-08-26 23:55:00.110: debug: Incrementing serial number in file "./example.net/zone.db"
461 2010-08-26 23:55:00.110: debug: Signing zone "example.net."
462 2010-08-26 23:55:00.111: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 EBE919 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
463 2010-08-26 23:55:00.168: debug: Cmd dnssec-signzone return: "zone.db.signed"
464 2010-08-26 23:55:00.169: debug: Signing completed after 0s.
465 2010-08-26 23:56:17.466: debug: Check RFC5011 status
466 2010-08-26 23:56:17.466: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
467 2010-08-26 23:56:17.466: debug: Check KSK status
468 2010-08-26 23:56:17.466: debug: Check ZSK status
469 2010-08-26 23:56:17.466: debug: Re-signing necessary: Modfied zone key set
470 2010-08-26 23:56:17.466: notice: "example.net.": re-signing triggered: Modfied zone key set
471 2010-08-26 23:56:17.466: debug: Writing key file "./example.net/dnskey.db"
472 2010-08-26 23:56:17.467: debug: Incrementing serial number in file "./example.net/zone.db"
473 2010-08-26 23:56:17.467: debug: Signing zone "example.net."
474 2010-08-26 23:56:17.467: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 A876E5 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
475 2010-08-26 23:56:17.531: debug: Cmd dnssec-signzone return: "zone.db.signed"
476 2010-08-26 23:56:17.531: debug: Signing completed after 0s.
477 2010-08-26 23:57:00.178: debug: Check RFC5011 status
478 2010-08-26 23:57:00.178: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
479 2010-08-26 23:57:00.178: debug: Check KSK status
480 2010-08-26 23:57:00.178: debug: Check ZSK status
481 2010-08-26 23:57:00.178: debug: Re-signing not necessary!
482 2010-08-26 23:57:00.178: debug: Check if there is a parent file to copy
483 2010-10-21 14:01:35.546: debug: Check RFC5011 status
484 2010-10-21 14:01:35.546: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
485 2010-10-21 14:01:35.546: debug: Check KSK status
486 2010-10-21 14:01:35.546: debug: Check ZSK status
487 2010-10-21 14:01:35.546: debug: Re-signing necessary: re-signing interval (2d) reached
488 2010-10-21 14:01:35.546: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
489 2010-10-21 14:01:35.546: debug: Writing key file "./example.net/dnskey.db"
490 2010-10-21 14:01:35.607: debug: Incrementing serial number in file "./example.net/zone.db"
491 2010-10-21 14:01:35.607: debug: Signing zone "example.net."
492 2010-10-21 14:01:35.607: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9FC981 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
493 2010-10-21 14:01:35.761: debug: Cmd dnssec-signzone return: "zone.db.signed"
494 2010-10-21 14:01:35.761: debug: Signing completed after 0s.
495 2010-10-21 14:02:09.209: debug: Check RFC5011 status
496 2010-10-21 14:02:09.209: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
497 2010-10-21 14:02:09.209: debug: Check KSK status
498 2010-10-21 14:02:09.209: debug: Check ZSK status
499 2010-10-21 14:02:09.209: debug: Re-signing not necessary!
500 2010-10-21 14:02:09.209: debug: Check if there is a parent file to copy
501 2010-10-21 14:05:36.170: debug: Check RFC5011 status
502 2010-10-21 14:05:36.170: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
503 2010-10-21 14:05:36.170: debug: Check KSK status
504 2010-10-21 14:05:36.170: debug: Check ZSK status
505 2010-10-21 14:05:36.170: debug: Re-signing not necessary!
506 2010-10-21 14:05:36.170: debug: Check if there is a parent file to copy
507 2010-10-21 14:30:43.892: debug: Check RFC5011 status
508 2010-10-21 14:30:43.892: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
509 2010-10-21 14:30:43.892: debug: Check KSK status
510 2010-10-21 14:30:43.892: debug: Check ZSK status
511 2010-10-21 14:30:43.892: debug: Re-signing not necessary!
512 2010-10-21 14:30:43.892: debug: Check if there is a parent file to copy
513 2014-11-14 18:04:37.729: debug: Check RFC5011 status
514 2014-11-14 18:04:37.729: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
515 2014-11-14 18:04:37.729: debug: Check KSK status
516 2014-11-14 18:04:37.729: debug: Check ZSK status
517 2014-11-14 18:04:37.729: debug: Re-signing necessary: Modified keys
518 2014-11-14 18:04:37.729: notice: "example.net.": re-signing triggered: Modified keys
519 2014-11-14 18:04:37.729: debug: Writing key file "./example.net/dnskey.db"
520 2014-11-14 18:04:37.730: debug: Incrementing serial number in file "./example.net/zone.db"
521 2014-11-14 18:04:37.730: debug: Signing zone "example.net."
522 2014-11-14 18:04:37.730: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 97195D -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
523 2014-11-14 18:04:37.827: debug: Cmd dnssec-signzone return: "zone.db.signed"
524 2014-11-14 18:04:37.827: debug: Signing completed after 0s.
525 2014-11-14 18:09:16.427: debug: Check RFC5011 status
526 2014-11-14 18:09:16.427: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
527 2014-11-14 18:09:16.427: debug: Check KSK status
528 2014-11-14 18:09:16.428: debug: No active KSK found: generate new one
529 2014-11-14 18:09:16.495: info: "example.net.": generated new KSK 44671
530 2014-11-14 18:09:16.495: debug: Check ZSK status
531 2014-11-14 18:09:16.495: debug: No active ZSK found: generate new one
532 2014-11-14 18:09:16.515: info: "example.net.": generated new ZSK 7929
533 2014-11-14 18:09:16.515: debug: New key for pre-publishing needed
534 2014-11-14 18:09:16.546: debug: ->creating new key 2253
535 2014-11-14 18:09:16.546: info: "example.net.": new key 2253 generated for pre-publishing
536 2014-11-14 18:09:16.546: debug: Re-signing necessary: Modified zone key set
537 2014-11-14 18:09:16.546: notice: "example.net.": re-signing triggered: Modified zone key set
538 2014-11-14 18:09:16.547: debug: Writing key file "./example.net/dnskey.db"
539 2014-11-14 18:09:16.547: debug: Incrementing serial number in file "./example.net/zone.db"
540 2014-11-14 18:09:16.547: debug: Signing zone "example.net."
541 2014-11-14 18:09:16.547: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 B26BB7 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
542 2014-11-14 18:09:16.646: debug: Cmd dnssec-signzone return: "zone.db.signed"
543 2014-11-14 18:09:16.646: debug: Signing completed after 0s.
544 2014-11-14 18:11:40.877: debug: Check RFC5011 status
545 2014-11-14 18:11:40.877: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
546 2014-11-14 18:11:40.877: debug: Check KSK status
547 2014-11-14 18:11:40.877: debug: Check ZSK status
548 2014-11-14 18:11:40.877: debug: Re-signing not necessary!
549 2014-11-14 18:11:40.877: debug: Check if there is a parent file to copy
550 2014-11-14 18:11:46.599: debug: Check RFC5011 status
551 2014-11-14 18:11:46.599: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
552 2014-11-14 18:11:46.599: debug: Check KSK status
553 2014-11-14 18:11:46.599: debug: Check ZSK status
554 2014-11-14 18:11:46.599: debug: Re-signing not necessary!
555 2014-11-14 18:11:46.599: debug: Check if there is a parent file to copy
556 2014-11-14 18:15:54.380: debug: Check RFC5011 status
557 2014-11-14 18:15:54.380: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
558 2014-11-14 18:15:54.380: debug: Check KSK status
559 2014-11-14 18:15:54.380: debug: Check ZSK status
560 2014-11-14 18:15:54.380: debug: Re-signing not necessary!
561 2014-11-14 18:15:54.380: debug: Check if there is a parent file to copy
562 2014-11-14 18:31:09.365: debug: Check RFC5011 status
563 2014-11-14 18:31:09.365: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
564 2014-11-14 18:31:09.365: debug: Check KSK status
565 2014-11-14 18:31:09.365: debug: Check ZSK status
566 2014-11-14 18:31:09.365: debug: Re-signing necessary: Modified keys
567 2014-11-14 18:31:09.365: notice: "example.net.": re-signing triggered: Modified keys
568 2014-11-14 18:31:09.365: debug: Writing key file "././example.net/dnskey.db"
569 2014-11-14 18:31:09.366: debug: Incrementing serial number in file "././example.net/zone.db"
570 2014-11-14 18:31:09.366: debug: Signing zone "example.net."
571 2014-11-14 18:31:09.366: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 8B4599 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
572 2014-11-14 18:31:09.488: debug: Cmd dnssec-signzone return: "zone.db.signed"
573 2014-11-14 18:31:09.488: debug: Signing completed after 0s.
574 2014-11-14 18:31:27.335: debug: Check RFC5011 status
575 2014-11-14 18:31:27.335: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
576 2014-11-14 18:31:27.335: debug: Check KSK status
577 2014-11-14 18:31:27.335: debug: Check ZSK status
578 2014-11-14 18:31:27.335: debug: Re-signing not necessary!
579 2014-11-14 18:31:27.335: debug: Check if there is a parent file to copy
580 2014-11-14 18:38:16.356: debug: Check RFC5011 status
581 2014-11-14 18:38:16.356: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
582 2014-11-14 18:38:16.356: debug: Check KSK status
583 2014-11-14 18:38:16.356: debug: Check ZSK status
584 2014-11-14 18:38:16.356: debug: Re-signing necessary: Modified keys
585 2014-11-14 18:38:16.356: notice: "example.net.": re-signing triggered: Modified keys
586 2014-11-14 18:38:16.356: debug: Writing key file "././example.net/dnskey.db"
587 2014-11-14 18:38:16.356: debug: Incrementing serial number in file "././example.net/zone.db"
588 2014-11-14 18:38:16.356: debug: Signing zone "example.net."
589 2014-11-14 18:38:16.356: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 BEBFB0 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
590 2014-11-14 18:38:16.484: debug: Cmd dnssec-signzone return: "zone.db.signed"
591 2014-11-14 18:38:16.484: debug: Signing completed after 0s.
592 2014-11-15 18:16:50.572: debug: Check RFC5011 status
593 2014-11-15 18:16:50.572: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
594 2014-11-15 18:16:50.572: debug: Check KSK status
595 2014-11-15 18:16:50.572: debug: Check ZSK status
596 2014-11-15 18:16:50.573: debug: Re-signing necessary: Modified keys
597 2014-11-15 18:16:50.573: notice: "example.net.": re-signing triggered: Modified keys
598 2014-11-15 18:16:50.573: debug: Writing key file "././example.net/dnskey.db"
599 2014-11-15 18:16:50.573: debug: Incrementing serial number in file "././example.net/zone.db"
600 2014-11-15 18:16:50.573: debug: Signing zone "example.net."
601 2014-11-15 18:16:50.573: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 DC5680 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
602 2014-11-15 18:16:50.715: debug: Cmd dnssec-signzone return: "zone.db.signed"
603 2014-11-15 18:16:50.715: debug: Signing completed after 0s.
604 2014-11-15 18:16:54.202: debug: Check RFC5011 status
605 2014-11-15 18:16:54.202: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
606 2014-11-15 18:16:54.202: debug: Check KSK status
607 2014-11-15 18:16:54.203: debug: Check ZSK status
608 2014-11-15 18:16:54.203: debug: Re-signing not necessary!
609 2014-11-15 18:16:54.203: debug: Check if there is a parent file to copy
610 2014-11-15 18:17:06.919: debug: Check RFC5011 status
611 2014-11-15 18:17:06.919: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
612 2014-11-15 18:17:06.919: debug: Check KSK status
613 2014-11-15 18:17:06.919: debug: Check ZSK status
614 2014-11-15 18:17:06.919: debug: Re-signing necessary: Modified keys
615 2014-11-15 18:17:06.919: notice: "example.net.": re-signing triggered: Modified keys
616 2014-11-15 18:17:06.919: debug: Writing key file "././example.net/dnskey.db"
617 2014-11-15 18:17:06.919: debug: Incrementing serial number in file "././example.net/zone.db"
618 2014-11-15 18:17:06.919: debug: Signing zone "example.net."
619 2014-11-15 18:17:06.919: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 D82F90 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
620 2014-11-15 18:17:07.040: debug: Cmd dnssec-signzone return: "zone.db.signed"
621 2014-11-15 18:17:07.040: debug: Signing completed after 1s.
622 2014-11-15 18:17:17.242: debug: Check RFC5011 status
623 2014-11-15 18:17:17.242: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
624 2014-11-15 18:17:17.242: debug: Check KSK status
625 2014-11-15 18:17:17.243: debug: Check ZSK status
626 2014-11-15 18:17:17.243: debug: Re-signing necessary: Zone file edited
627 2014-11-15 18:17:17.243: notice: "example.net.": re-signing triggered: Zone file edited
628 2014-11-15 18:17:17.243: debug: Writing key file "././example.net/dnskey.db"
629 2014-11-15 18:17:17.243: debug: Incrementing serial number in file "././example.net/zone.db"
630 2014-11-15 18:17:17.243: debug: Signing zone "example.net."
631 2014-11-15 18:17:17.243: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 603310 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
632 2014-11-15 18:17:17.365: debug: Cmd dnssec-signzone return: "zone.db.signed"
633 2014-11-15 18:17:17.365: debug: Signing completed after 0s.
634 2014-11-17 19:12:44.250: debug: Check RFC5011 status
635 2014-11-17 19:12:44.250: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
636 2014-11-17 19:12:44.250: debug: Check KSK status
637 2014-11-17 19:12:44.250: debug: Check ZSK status
638 2014-11-17 19:12:44.250: debug: Re-signing necessary: re-signing interval (2d) reached
639 2014-11-17 19:12:44.250: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
640 2014-11-17 19:12:44.250: debug: Writing key file "./example.net/dnskey.db"
641 2014-11-17 19:12:44.251: debug: Incrementing serial number in file "./example.net/zone.db"
642 2014-11-17 19:12:44.251: debug: Signing zone "example.net."
643 2014-11-17 19:12:44.251: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 9F5882 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
644 2014-11-17 19:12:44.392: debug: Cmd dnssec-signzone return: "zone.db.signed"
645 2014-11-17 19:12:44.392: debug: Signing completed after 0s.
646 2014-11-17 19:12:49.692: debug: Check RFC5011 status
647 2014-11-17 19:12:49.692: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
648 2014-11-17 19:12:49.692: debug: Check KSK status
649 2014-11-17 19:12:49.692: debug: Check ZSK status
650 2014-11-17 19:12:49.692: debug: Re-signing not necessary!
651 2014-11-17 19:12:49.692: debug: Check if there is a parent file to copy
652 2014-11-17 19:13:02.603: debug: Check RFC5011 status
653 2014-11-17 19:13:02.603: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
654 2014-11-17 19:13:02.603: debug: Check KSK status
655 2014-11-17 19:13:02.603: debug: Check ZSK status
656 2014-11-17 19:13:02.603: debug: Re-signing not necessary!
657 2014-11-17 19:13:02.603: debug: Check if there is a parent file to copy
658 2014-11-17 19:13:50.410: debug: Check RFC5011 status
659 2014-11-17 19:13:50.410: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
660 2014-11-17 19:13:50.410: debug: Check KSK status
661 2014-11-17 19:13:50.410: debug: Check ZSK status
662 2014-11-17 19:13:50.410: debug: Re-signing necessary: Modified keys
663 2014-11-17 19:13:50.410: notice: "example.net.": re-signing triggered: Modified keys
664 2014-11-17 19:13:50.410: debug: Writing key file "./example.net/dnskey.db"
665 2014-11-17 19:13:50.410: debug: Incrementing serial number in file "./example.net/zone.db"
666 2014-11-17 19:13:50.410: debug: Signing zone "example.net."
667 2014-11-17 19:13:50.411: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 053453 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
668 2014-11-17 19:13:50.525: debug: Cmd dnssec-signzone return: "zone.db.signed"
669 2014-11-17 19:13:50.525: debug: Signing completed after 0s.
670 2014-11-17 19:13:54.302: debug: Check RFC5011 status
671 2014-11-17 19:13:54.302: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
672 2014-11-17 19:13:54.302: debug: Check KSK status
673 2014-11-17 19:13:54.302: debug: Check ZSK status
674 2014-11-17 19:13:54.302: debug: Re-signing not necessary!
675 2014-11-17 19:13:54.302: debug: Check if there is a parent file to copy
676 2014-11-17 19:14:01.846: debug: Check RFC5011 status
677 2014-11-17 19:14:01.846: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
678 2014-11-17 19:14:01.846: debug: Check KSK status
679 2014-11-17 19:14:01.846: debug: Check ZSK status
680 2014-11-17 19:14:01.846: debug: Re-signing necessary: Zone file edited
681 2014-11-17 19:14:01.846: notice: "example.net.": re-signing triggered: Zone file edited
682 2014-11-17 19:14:01.846: debug: Writing key file "./example.net/dnskey.db"
683 2014-11-17 19:14:01.846: debug: Incrementing serial number in file "./example.net/zone.db"
684 2014-11-17 19:14:01.846: debug: Signing zone "example.net."
685 2014-11-17 19:14:01.847: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -A -3 7CF530 -C -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
686 2014-11-17 19:14:01.969: debug: Cmd dnssec-signzone return: "zone.db.signed"
687 2014-11-17 19:14:01.969: debug: Signing completed after 0s.