+++ /dev/null
-2008-12-18 01:02:56.187: notice: ------------------------------------------------------------
-2008-12-18 01:02:56.187: notice: running ../../dnssec-signer -v -v
-2008-12-18 01:02:56.589: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2008-12-18 01:02:56.589: debug: Check RFC5011 status
-2008-12-18 01:02:56.589: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2008-12-18 01:02:56.589: debug: Check KSK status
-2008-12-18 01:02:56.589: debug: Check ZSK status
-2008-12-18 01:02:56.590: debug: Lifetime(390 sec) of depreciated key 45361 exceeded (124287 sec)
-2008-12-18 01:02:56.590: info: "sub.example.net.": old ZSK 45361 removed
-2008-12-18 01:02:56.604: debug: ->remove it
-2008-12-18 01:02:56.604: debug: Re-signing necessary: Modfied zone key set
-2008-12-18 01:02:56.604: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2008-12-18 01:02:56.604: debug: Writing key file "./sub.example.net/dnskey.db"
-2008-12-18 01:02:56.605: debug: Signing zone "sub.example.net."
-2008-12-18 01:02:56.605: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -3 BE70E4 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2008-12-18 01:02:56.970: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-18 01:02:56.971: debug: Signing completed after 0s.
-2008-12-18 01:02:56.971: debug:
-2008-12-18 01:02:56.971: debug: parsing zone "example.net." in dir "./example.net"
-2008-12-18 01:02:56.971: debug: Check RFC5011 status
-2008-12-18 01:02:56.971: debug: Check ZSK status
-2008-12-18 01:02:56.971: debug: Re-signing necessary: Zone file edited
-2008-12-18 01:02:56.971: notice: "example.net.": re-signing triggered: Zone file edited
-2008-12-18 01:02:56.972: debug: Writing key file "./example.net/dnskey.db"
-2008-12-18 01:02:56.972: debug: Incrementing serial number in file "./example.net/zone.db"
-2008-12-18 01:02:56.973: debug: Signing zone "example.net."
-2008-12-18 01:02:56.973: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2008-12-18 01:02:57.106: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-18 01:02:57.106: debug: Signing completed after 1s.
-2008-12-18 01:02:57.106: debug:
-2008-12-18 01:02:57.106: notice: end of run: 0 errors occured
-2008-12-18 01:03:01.191: notice: ------------------------------------------------------------
-2008-12-18 01:03:01.192: notice: running ../../dnssec-signer -d -v -v
-2008-12-18 01:03:01.194: debug: parsing zone "dyn.example.net." in dir "./dyn.example.net"
-2008-12-18 01:03:01.194: debug: Check RFC5011 status
-2008-12-18 01:03:01.194: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2008-12-18 01:03:01.194: debug: Check KSK status
-2008-12-18 01:03:01.194: warning: "dyn.example.net.": lifetime of key signing key 42138 exceeded since 10w4d3h1m4s
-2008-12-18 01:03:01.194: debug: Check ZSK status
-2008-12-18 01:03:01.195: debug: Lifetime(1209600 +/-150 sec) of active key 1355 exceeded (11588464 sec)
-2008-12-18 01:03:01.195: debug: ->depreciate it
-2008-12-18 01:03:01.195: debug: ->activate published key 10643
-2008-12-18 01:03:01.195: notice: "dyn.example.net.": lifetime of zone signing key 1355 exceeded: ZSK rollover done
-2008-12-18 01:03:01.196: debug: Re-signing necessary: Modfied zone key set
-2008-12-18 01:03:01.196: notice: "dyn.example.net.": re-signing triggered: Modfied zone key set
-2008-12-18 01:03:01.196: debug: Writing key file "./dyn.example.net/dnskey.db"
-2008-12-18 01:03:01.196: debug: Signing zone "dyn.example.net."
-2008-12-18 01:03:01.196: notice: "dyn.example.net.": freeze dynamic zone
-2008-12-18 01:03:01.196: debug: freeze dynamic zone "dyn.example.net."
-2008-12-18 01:03:01.197: debug: Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
-2008-12-18 01:03:01.628: debug: Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
-2008-12-18 01:03:01.653: debug: Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o dyn.example.net. -e +518400 -N increment -f zone.db.dsigned zone.db K*.private"
-2008-12-18 01:03:01.792: debug: Cmd dnssec-signzone return: "zone.db.dsigned"
-2008-12-18 01:03:01.792: notice: "dyn.example.net.": thaw dynamic zone
-2008-12-18 01:03:01.792: debug: thaw dynamic zone "dyn.example.net."
-2008-12-18 01:03:01.792: debug: Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
-2008-12-18 01:03:01.802: debug: Signing completed after 0s.
-2008-12-18 01:03:01.802: debug:
-2008-12-18 01:03:01.802: notice: end of run: 0 errors occured
-2008-12-28 23:06:27.762: notice: ------------------------------------------------------------
-2008-12-28 23:06:27.762: notice: running ../../dnssec-signer -v -v
-2008-12-28 23:06:27.764: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2008-12-28 23:06:27.765: debug: Check RFC5011 status
-2008-12-28 23:06:27.765: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2008-12-28 23:06:27.765: debug: Check KSK status
-2008-12-28 23:06:27.765: debug: Check ZSK status
-2008-12-28 23:06:27.765: debug: Lifetime(259200 +/-150 sec) of active key 22440 exceeded (1067698 sec)
-2008-12-28 23:06:27.765: debug: ->depreciate it
-2008-12-28 23:06:27.766: debug: ->activate published key 5823
-2008-12-28 23:06:27.766: notice: "sub.example.net.": lifetime of zone signing key 22440 exceeded: ZSK rollover done
-2008-12-28 23:06:27.766: debug: New key for publishing needed
-2008-12-28 23:06:28.696: debug: ->creating new key 4710
-2008-12-28 23:06:28.696: info: "sub.example.net.": new key 4710 generated for publishing
-2008-12-28 23:06:28.696: debug: Re-signing necessary: Modfied zone key set
-2008-12-28 23:06:28.696: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2008-12-28 23:06:28.696: debug: Writing key file "./sub.example.net/dnskey.db"
-2008-12-28 23:06:28.697: debug: Signing zone "sub.example.net."
-2008-12-28 23:06:28.697: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -3 B9D9AA -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2008-12-28 23:06:28.804: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-28 23:06:28.804: debug: Signing completed after 0s.
-2008-12-28 23:06:28.804: debug:
-2008-12-28 23:06:28.804: debug: parsing zone "example.net." in dir "./example.net"
-2008-12-28 23:06:28.804: debug: Check RFC5011 status
-2008-12-28 23:06:28.804: debug: Check ZSK status
-2008-12-28 23:06:28.804: debug: Re-signing necessary: re-signing interval (2d) reached
-2008-12-28 23:06:28.804: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
-2008-12-28 23:06:28.804: debug: Writing key file "./example.net/dnskey.db"
-2008-12-28 23:06:28.805: debug: Incrementing serial number in file "./example.net/zone.db"
-2008-12-28 23:06:28.805: debug: Signing zone "example.net."
-2008-12-28 23:06:28.805: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2008-12-28 23:06:28.898: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-28 23:06:28.898: debug: Signing completed after 0s.
-2008-12-28 23:06:28.898: debug:
-2008-12-28 23:06:28.899: notice: end of run: 0 errors occured
-2008-12-28 23:07:39.896: notice: ------------------------------------------------------------
-2008-12-28 23:07:39.896: notice: running ../../dnssec-signer -v -v -N named.conf
-2008-12-28 23:07:39.899: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2008-12-28 23:07:39.899: debug: Check RFC5011 status
-2008-12-28 23:07:39.899: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2008-12-28 23:07:39.899: debug: Check KSK status
-2008-12-28 23:07:39.899: debug: Check ZSK status
-2008-12-28 23:07:39.899: debug: Re-signing not necessary!
-2008-12-28 23:07:39.899: debug: Check if there is a parent file to copy
-2008-12-28 23:07:39.899: debug:
-2008-12-28 23:07:39.899: debug: parsing zone "example.net." in dir "././example.net"
-2008-12-28 23:07:39.899: debug: Check RFC5011 status
-2008-12-28 23:07:39.899: debug: Check ZSK status
-2008-12-28 23:07:39.899: debug: Re-signing not necessary!
-2008-12-28 23:07:39.899: debug: Check if there is a parent file to copy
-2008-12-28 23:07:39.899: debug:
-2008-12-28 23:07:39.899: notice: end of run: 0 errors occured
-2008-12-28 23:08:02.141: notice: ------------------------------------------------------------
-2008-12-28 23:08:02.141: notice: running ../../dnssec-signer -f -v -v -N named.conf
-2008-12-28 23:08:02.143: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2008-12-28 23:08:02.143: debug: Check RFC5011 status
-2008-12-28 23:08:02.143: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2008-12-28 23:08:02.143: debug: Check KSK status
-2008-12-28 23:08:02.143: debug: Check ZSK status
-2008-12-28 23:08:02.143: debug: Re-signing necessary: Option -f
-2008-12-28 23:08:02.143: notice: "sub.example.net.": re-signing triggered: Option -f
-2008-12-28 23:08:02.143: debug: Writing key file "././sub.example.net/dnskey.db"
-2008-12-28 23:08:02.144: debug: Signing zone "sub.example.net."
-2008-12-28 23:08:02.144: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -3 B5EA98 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2008-12-28 23:08:02.266: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-28 23:08:02.266: debug: Signing completed after 0s.
-2008-12-28 23:08:02.266: debug:
-2008-12-28 23:08:02.266: debug: parsing zone "example.net." in dir "././example.net"
-2008-12-28 23:08:02.266: debug: Check RFC5011 status
-2008-12-28 23:08:02.266: debug: Check ZSK status
-2008-12-28 23:08:02.266: debug: Re-signing necessary: Option -f
-2008-12-28 23:08:02.266: notice: "example.net.": re-signing triggered: Option -f
-2008-12-28 23:08:02.266: debug: Writing key file "././example.net/dnskey.db"
-2008-12-28 23:08:02.267: debug: Incrementing serial number in file "././example.net/zone.db"
-2008-12-28 23:08:02.267: debug: Signing zone "example.net."
-2008-12-28 23:08:02.267: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2008-12-28 23:08:02.534: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2008-12-28 23:08:02.534: debug: Signing completed after 0s.
-2008-12-28 23:08:02.534: debug:
-2008-12-28 23:08:02.534: notice: end of run: 0 errors occured
-2009-02-28 12:31:26.082: notice: ------------------------------------------------------------
-2009-02-28 12:31:26.083: notice: running ../../dnssec-signer -N named.conf
-2009-02-28 12:31:26.100: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-02-28 12:31:26.100: debug: Check RFC5011 status
-2009-02-28 12:31:26.100: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-02-28 12:31:26.100: debug: Check KSK status
-2009-02-28 12:31:26.100: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 1d12h35m58s
-2009-02-28 12:31:26.100: debug: Check ZSK status
-2009-02-28 12:31:26.100: debug: Lifetime(390 sec) of depreciated key 22440 exceeded (5315758 sec)
-2009-02-28 12:31:26.100: info: "sub.example.net.": old ZSK 22440 removed
-2009-02-28 12:31:26.101: debug: ->remove it
-2009-02-28 12:31:26.101: debug: Lifetime(259200 +/-150 sec) of active key 5823 exceeded (5315758 sec)
-2009-02-28 12:31:26.101: debug: ->depreciate it
-2009-02-28 12:31:26.101: debug: ->activate published key 4710
-2009-02-28 12:31:26.101: notice: "sub.example.net.": lifetime of zone signing key 5823 exceeded: ZSK rollover done
-2009-02-28 12:31:26.101: debug: New key for publishing needed
-2009-02-28 12:31:28.559: debug: ->creating new key 32820
-2009-02-28 12:31:28.559: info: "sub.example.net.": new key 32820 generated for publishing
-2009-02-28 12:31:28.559: debug: Re-signing necessary: Modfied zone key set
-2009-02-28 12:31:28.560: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-02-28 12:31:28.560: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-02-28 12:31:28.560: debug: Signing zone "sub.example.net."
-2009-02-28 12:31:28.560: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -3 FC6C7C -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-02-28 12:31:28.803: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-02-28 12:31:28.803: debug: Signing completed after 0s.
-2009-02-28 12:31:28.803: debug:
-2009-02-28 12:31:28.803: debug: parsing zone "example.net." in dir "././example.net"
-2009-02-28 12:31:28.803: debug: Check RFC5011 status
-2009-02-28 12:31:28.803: notice: "example.net.": starting rfc5011 rollover
-2009-02-28 12:31:28.803: debug: Lifetime of Key Signing Key 1764 exceeded (8w5d12h36m): Starting rfc5011 rollover!
-2009-02-28 12:31:28.803: debug: =>Generating new standby key signing key
-2009-02-28 12:31:29.067: info: "example.net.": generated new standby KSK 33840
-2009-02-28 12:31:29.067: debug: =>Activating old standby key 7308
-2009-02-28 12:31:29.068: debug: =>Revoking old active key 1764
-2009-02-28 12:31:29.068: debug: Check ZSK status
-2009-02-28 12:31:29.068: debug: Re-signing necessary: Modfied zone key set
-2009-02-28 12:31:29.068: notice: "example.net.": re-signing triggered: Modfied zone key set
-2009-02-28 12:31:29.068: debug: Writing key file "././example.net/dnskey.db"
-2009-02-28 12:31:29.069: debug: Incrementing serial number in file "././example.net/zone.db"
-2009-02-28 12:31:29.069: debug: Signing zone "example.net."
-2009-02-28 12:31:29.069: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-02-28 12:31:29.206: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-02-28 12:31:29.206: debug: Signing completed after 0s.
-2009-02-28 12:31:29.206: debug:
-2009-02-28 12:31:29.206: notice: end of run: 0 errors occured
-2009-02-28 12:31:34.121: notice: ------------------------------------------------------------
-2009-02-28 12:31:34.121: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:31:34.126: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-02-28 12:31:34.126: debug: Check RFC5011 status
-2009-02-28 12:31:34.126: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-02-28 12:31:34.126: debug: Check KSK status
-2009-02-28 12:31:34.126: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 1d12h36m6s
-2009-02-28 12:31:34.126: debug: Check ZSK status
-2009-02-28 12:31:34.126: debug: Re-signing not necessary!
-2009-02-28 12:31:34.126: debug: Check if there is a parent file to copy
-2009-02-28 12:31:34.126: debug:
-2009-02-28 12:31:34.126: debug: parsing zone "example.net." in dir "././example.net"
-2009-02-28 12:31:34.126: debug: Check RFC5011 status
-2009-02-28 12:31:34.126: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-02-28 12:31:34.126: debug: Check ZSK status
-2009-02-28 12:31:34.126: debug: Re-signing not necessary!
-2009-02-28 12:31:34.126: debug: Check if there is a parent file to copy
-2009-02-28 12:31:34.126: debug:
-2009-02-28 12:31:34.126: notice: end of run: 0 errors occured
-2009-02-28 12:32:49.522: notice: ------------------------------------------------------------
-2009-02-28 12:32:49.522: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:32:49.525: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-02-28 12:32:49.525: debug: Check RFC5011 status
-2009-02-28 12:32:49.525: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-02-28 12:32:49.525: debug: Check KSK status
-2009-02-28 12:32:49.525: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 1d12h37m21s
-2009-02-28 12:32:49.525: debug: Check ZSK status
-2009-02-28 12:32:49.526: debug: Re-signing not necessary!
-2009-02-28 12:32:49.526: debug: Check if there is a parent file to copy
-2009-02-28 12:32:49.526: debug:
-2009-02-28 12:32:49.526: debug: parsing zone "example.net." in dir "././example.net"
-2009-02-28 12:32:49.526: debug: Check RFC5011 status
-2009-02-28 12:32:49.526: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-02-28 12:32:49.526: debug: Check ZSK status
-2009-02-28 12:32:49.526: debug: Re-signing not necessary!
-2009-02-28 12:32:49.526: debug: Check if there is a parent file to copy
-2009-02-28 12:32:49.527: debug:
-2009-02-28 12:32:49.527: notice: end of run: 0 errors occured
-2009-02-28 12:42:47.999: notice: ------------------------------------------------------------
-2009-02-28 12:42:48.000: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:45:56.491: notice: ------------------------------------------------------------
-2009-02-28 12:45:56.491: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:50:13.057: notice: ------------------------------------------------------------
-2009-02-28 12:50:13.057: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:50:54.700: notice: ------------------------------------------------------------
-2009-02-28 12:50:54.700: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:52:23.926: notice: ------------------------------------------------------------
-2009-02-28 12:52:23.926: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:52:23.933: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-02-28 12:52:23.934: debug: Check RFC5011 status
-2009-02-28 12:52:23.934: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-02-28 12:52:23.934: debug: Check KSK status
-2009-02-28 12:52:23.934: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 1d12h56m55s
-2009-02-28 12:52:23.934: debug: Check ZSK status
-2009-02-28 12:52:23.934: debug: Lifetime(390 sec) of depreciated key 5823 exceeded (1257 sec)
-2009-02-28 12:52:23.934: info: "sub.example.net.": old ZSK 5823 removed
-2009-02-28 12:52:23.934: debug: ->remove it
-2009-02-28 12:52:23.934: debug: Re-signing necessary: Modfied zone key set
-2009-02-28 12:52:23.934: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-02-28 12:52:23.934: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-02-28 12:52:23.935: debug: Signing zone "sub.example.net."
-2009-02-28 12:52:23.935: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -3 A4756D -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-02-28 12:52:24.701: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-02-28 12:52:24.701: debug: Signing completed after 1s.
-2009-02-28 12:52:24.701: debug:
-2009-02-28 12:52:24.701: debug: parsing zone "example.net." in dir "././example.net"
-2009-02-28 12:52:24.701: debug: Check RFC5011 status
-2009-02-28 12:52:24.701: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-02-28 12:52:24.701: debug: Check ZSK status
-2009-02-28 12:52:24.701: debug: Re-signing not necessary!
-2009-02-28 12:52:24.701: debug: Check if there is a parent file to copy
-2009-02-28 12:52:24.701: debug:
-2009-02-28 12:52:24.701: notice: end of run: 0 errors occured
-2009-02-28 12:53:08.325: notice: ------------------------------------------------------------
-2009-02-28 12:53:08.325: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:53:48.858: notice: ------------------------------------------------------------
-2009-02-28 12:53:48.858: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:54:09.878: notice: ------------------------------------------------------------
-2009-02-28 12:54:09.878: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-02-28 12:54:09.885: debug: parsing zone "sub.example.net." in dir "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./sub.example.net"
-2009-02-28 12:54:09.885: debug: Check RFC5011 status
-2009-02-28 12:54:09.885: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-02-28 12:54:09.885: debug: Check KSK status
-2009-02-28 12:54:09.886: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 1d12h58m41s
-2009-02-28 12:54:09.886: debug: Check ZSK status
-2009-02-28 12:54:09.886: debug: Re-signing not necessary!
-2009-02-28 12:54:09.886: debug: Check if there is a parent file to copy
-2009-02-28 12:54:09.886: debug:
-2009-02-28 12:54:09.886: debug: parsing zone "example.net." in dir "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./example.net"
-2009-02-28 12:54:09.886: debug: Check RFC5011 status
-2009-02-28 12:54:09.886: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-02-28 12:54:09.886: debug: Check ZSK status
-2009-02-28 12:54:09.886: debug: Re-signing not necessary!
-2009-02-28 12:54:09.886: debug: Check if there is a parent file to copy
-2009-02-28 12:54:09.886: debug:
-2009-02-28 12:54:09.886: notice: end of run: 0 errors occured
-2009-02-28 12:55:02.579: notice: ------------------------------------------------------------
-2009-02-28 12:55:02.579: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-03-03 19:13:47.524: notice: ------------------------------------------------------------
-2009-03-03 19:13:47.524: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-03-03 19:13:47.532: debug: parsing zone "sub.example.net." in dir "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./sub.example.net"
-2009-03-03 19:13:47.532: debug: Check RFC5011 status
-2009-03-03 19:13:47.532: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-03 19:13:47.532: debug: Check KSK status
-2009-03-03 19:13:47.533: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 4d19h18m19s
-2009-03-03 19:13:47.533: debug: Check ZSK status
-2009-03-03 19:13:47.533: debug: Lifetime(259200 +/-150 sec) of active key 4710 exceeded (283341 sec)
-2009-03-03 19:13:47.533: debug: ->depreciate it
-2009-03-03 19:13:47.533: debug: ->activate published key 32820
-2009-03-03 19:13:47.533: notice: "sub.example.net.": lifetime of zone signing key 4710 exceeded: ZSK rollover done
-2009-03-03 19:13:47.533: debug: New key for publishing needed
-2009-03-03 19:13:48.366: debug: ->creating new key 49656
-2009-03-03 19:13:48.366: info: "sub.example.net.": new key 49656 generated for publishing
-2009-03-03 19:13:48.366: debug: Re-signing necessary: Modfied zone key set
-2009-03-03 19:13:48.366: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-03-03 19:13:48.367: debug: Writing key file "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./sub.example.net/dnskey.db"
-2009-03-03 19:13:48.367: debug: Signing zone "sub.example.net."
-2009-03-03 19:13:48.367: debug: Run cmd "cd /home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./sub.example.net; /usr/local/sbin/dnssec-signzone -3 BCB121 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-03-03 19:13:48.543: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-03 19:13:48.543: debug: Signing completed after 0s.
-2009-03-03 19:13:48.543: debug:
-2009-03-03 19:13:48.543: debug: parsing zone "example.net." in dir "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./example.net"
-2009-03-03 19:13:48.543: debug: Check RFC5011 status
-2009-03-03 19:13:48.543: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-03-03 19:13:48.543: debug: Check ZSK status
-2009-03-03 19:13:48.543: debug: Re-signing necessary: re-signing interval (2d) reached
-2009-03-03 19:13:48.543: notice: "example.net.": re-signing triggered: re-signing interval (2d) reached
-2009-03-03 19:13:48.543: debug: Writing key file "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./example.net/dnskey.db"
-2009-03-03 19:13:48.544: debug: Incrementing serial number in file "/home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./example.net/zone.db"
-2009-03-03 19:13:48.544: debug: Signing zone "example.net."
-2009-03-03 19:13:48.544: debug: Run cmd "cd /home/hoz/share/named/dnssec-signer/zkt-0.99/examples/flat/./example.net; /usr/local/sbin/dnssec-signzone -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-03-03 19:13:48.723: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-03 19:13:48.723: debug: Signing completed after 0s.
-2009-03-03 19:13:48.723: debug:
-2009-03-03 19:13:48.724: notice: end of run: 0 errors occured
-2009-03-03 19:14:16.121: notice: ------------------------------------------------------------
-2009-03-03 19:14:16.121: notice: running ../../dnssec-signer -O namedchrootdir: /var/named -v -v -N named.conf
-2009-03-03 19:14:30.231: notice: ------------------------------------------------------------
-2009-03-03 19:14:30.231: notice: running ../../dnssec-signer -O namedchrootdir: . -v -v -N named.conf
-2009-03-03 19:15:37.851: notice: ------------------------------------------------------------
-2009-03-03 19:15:37.851: notice: running ../../dnssec-signer -O namedchrootdir: . -v -v -N named.conf
-2009-03-03 19:15:37.853: debug: parsing zone "sub.example.net." in dir "./././sub.example.net"
-2009-03-03 19:15:37.853: debug: Check RFC5011 status
-2009-03-03 19:15:37.853: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-03 19:15:37.853: debug: Check KSK status
-2009-03-03 19:15:37.853: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 4d19h20m9s
-2009-03-03 19:15:37.853: debug: Check ZSK status
-2009-03-03 19:15:37.853: debug: Re-signing not necessary!
-2009-03-03 19:15:37.853: debug: Check if there is a parent file to copy
-2009-03-03 19:15:37.853: debug:
-2009-03-03 19:15:37.853: debug: parsing zone "example.net." in dir "./././example.net"
-2009-03-03 19:15:37.853: debug: Check RFC5011 status
-2009-03-03 19:15:37.853: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-03-03 19:15:37.853: debug: Check ZSK status
-2009-03-03 19:15:37.853: debug: Re-signing not necessary!
-2009-03-03 19:15:37.853: debug: Check if there is a parent file to copy
-2009-03-03 19:15:37.853: debug:
-2009-03-03 19:15:37.853: notice: end of run: 0 errors occured
-2009-03-03 19:15:44.219: notice: ------------------------------------------------------------
-2009-03-03 19:15:44.219: notice: running ../../dnssec-signer -O namedchrootdir: /var/named -v -v -N named.conf
-2009-03-03 19:15:49.305: notice: ------------------------------------------------------------
-2009-03-03 19:15:49.305: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-03-03 19:15:49.308: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-03 19:15:49.308: debug: Check RFC5011 status
-2009-03-03 19:15:49.308: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-03 19:15:49.308: debug: Check KSK status
-2009-03-03 19:15:49.309: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 4d19h20m21s
-2009-03-03 19:15:49.309: debug: Check ZSK status
-2009-03-03 19:15:49.309: debug: Re-signing not necessary!
-2009-03-03 19:15:49.309: debug: Check if there is a parent file to copy
-2009-03-03 19:15:49.309: debug:
-2009-03-03 19:15:49.309: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-03 19:15:49.310: debug: Check RFC5011 status
-2009-03-03 19:15:49.310: debug: zone "example.net.": found revoked key with exptime of: Feb 28 2009 12:31:28
-2009-03-03 19:15:49.310: debug: Check ZSK status
-2009-03-03 19:15:49.310: debug: Re-signing not necessary!
-2009-03-03 19:15:49.310: debug: Check if there is a parent file to copy
-2009-03-03 19:15:49.310: debug:
-2009-03-03 19:15:49.310: notice: end of run: 0 errors occured
-2009-03-04 18:07:38.441: notice: ------------------------------------------------------------
-2009-03-04 18:07:38.441: notice: running ../../dnssec-signer -v -v -N named.conf
-2009-03-04 18:07:38.459: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:07:38.459: debug: Check RFC5011 status
-2009-03-04 18:07:38.459: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:07:38.459: debug: Check KSK status
-2009-03-04 18:07:38.459: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h12m10s
-2009-03-04 18:07:38.459: debug: Check ZSK status
-2009-03-04 18:07:38.459: debug: Lifetime(390 sec) of depreciated key 4710 exceeded (82431 sec)
-2009-03-04 18:07:38.459: info: "sub.example.net.": old ZSK 4710 removed
-2009-03-04 18:07:38.459: debug: ->remove it
-2009-03-04 18:07:38.459: debug: Re-signing necessary: Modfied zone key set
-2009-03-04 18:07:38.459: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-03-04 18:07:38.459: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-03-04 18:07:38.460: debug: Signing zone "sub.example.net."
-2009-03-04 18:07:38.460: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -n 0 -3 33B698 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-03-04 18:07:38.635: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:07:38.635: debug: Signing completed after 0s.
-2009-03-04 18:07:38.635: debug:
-2009-03-04 18:07:38.635: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:07:38.635: debug: Check RFC5011 status
-2009-03-04 18:07:38.635: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:07:38.636: debug: Check ZSK status
-2009-03-04 18:07:38.636: debug: Re-signing not necessary!
-2009-03-04 18:07:38.636: debug: Check if there is a parent file to copy
-2009-03-04 18:07:38.636: debug:
-2009-03-04 18:07:38.636: notice: end of run: 0 errors occured
-2009-03-04 18:07:54.353: notice: ------------------------------------------------------------
-2009-03-04 18:07:54.353: notice: running ../../dnssec-signer -r -v -v -N named.conf
-2009-03-04 18:07:54.357: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:07:54.357: debug: Check RFC5011 status
-2009-03-04 18:07:54.357: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:07:54.357: debug: Check KSK status
-2009-03-04 18:07:54.357: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h12m26s
-2009-03-04 18:07:54.357: debug: Check ZSK status
-2009-03-04 18:07:54.357: debug: Re-signing not necessary!
-2009-03-04 18:07:54.357: debug: Check if there is a parent file to copy
-2009-03-04 18:07:54.357: debug:
-2009-03-04 18:07:54.357: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:07:54.357: debug: Check RFC5011 status
-2009-03-04 18:07:54.357: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:07:54.358: debug: Check ZSK status
-2009-03-04 18:07:54.358: debug: Re-signing not necessary!
-2009-03-04 18:07:54.358: debug: Check if there is a parent file to copy
-2009-03-04 18:07:54.358: debug:
-2009-03-04 18:07:54.358: notice: end of run: 0 errors occured
-2009-03-04 18:08:25.210: notice: ------------------------------------------------------------
-2009-03-04 18:08:25.210: notice: running ../../dnssec-signer -r -v -v -N named.conf
-2009-03-04 18:08:25.212: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:08:25.212: debug: Check RFC5011 status
-2009-03-04 18:08:25.213: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:08:25.213: debug: Check KSK status
-2009-03-04 18:08:25.213: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h12m57s
-2009-03-04 18:08:25.213: debug: Check ZSK status
-2009-03-04 18:08:25.213: debug: Re-signing not necessary!
-2009-03-04 18:08:25.213: debug: Check if there is a parent file to copy
-2009-03-04 18:08:25.213: debug:
-2009-03-04 18:08:25.214: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:08:25.214: debug: Check RFC5011 status
-2009-03-04 18:08:25.214: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:08:25.214: debug: Check ZSK status
-2009-03-04 18:08:25.214: debug: Re-signing not necessary!
-2009-03-04 18:08:25.214: debug: Check if there is a parent file to copy
-2009-03-04 18:08:25.214: debug:
-2009-03-04 18:08:25.216: notice: end of run: 0 errors occured
-2009-03-04 18:08:32.379: notice: ------------------------------------------------------------
-2009-03-04 18:08:32.379: notice: running ../../dnssec-signer -f -v -v -N named.conf
-2009-03-04 18:08:32.381: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:08:32.381: debug: Check RFC5011 status
-2009-03-04 18:08:32.381: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:08:32.381: debug: Check KSK status
-2009-03-04 18:08:32.381: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h13m4s
-2009-03-04 18:08:32.381: debug: Check ZSK status
-2009-03-04 18:08:32.381: debug: Re-signing necessary: Option -f
-2009-03-04 18:08:32.381: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-03-04 18:08:32.381: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-03-04 18:08:32.382: debug: Signing zone "sub.example.net."
-2009-03-04 18:08:32.382: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -n 2 -3 A0BEB8 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-03-04 18:08:32.896: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:08:32.896: debug: Signing completed after 0s.
-2009-03-04 18:08:32.896: debug:
-2009-03-04 18:08:32.896: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:08:32.896: debug: Check RFC5011 status
-2009-03-04 18:08:32.896: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:08:32.896: debug: Check ZSK status
-2009-03-04 18:08:32.896: debug: Re-signing necessary: Option -f
-2009-03-04 18:08:32.896: notice: "example.net.": re-signing triggered: Option -f
-2009-03-04 18:08:32.896: debug: Writing key file "././example.net/dnskey.db"
-2009-03-04 18:08:32.897: debug: Incrementing serial number in file "././example.net/zone.db"
-2009-03-04 18:08:32.897: debug: Signing zone "example.net."
-2009-03-04 18:08:32.897: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 2 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-03-04 18:08:33.042: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:08:33.042: debug: Signing completed after 1s.
-2009-03-04 18:08:33.042: debug:
-2009-03-04 18:08:33.043: notice: end of run: 0 errors occured
-2009-03-04 18:08:46.381: notice: ------------------------------------------------------------
-2009-03-04 18:08:46.381: notice: running ../../dnssec-signer -f -v -v -N named.conf
-2009-03-04 18:08:46.385: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:08:46.385: debug: Check RFC5011 status
-2009-03-04 18:08:46.385: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:08:46.385: debug: Check KSK status
-2009-03-04 18:08:46.385: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h13m18s
-2009-03-04 18:08:46.385: debug: Check ZSK status
-2009-03-04 18:08:46.385: debug: Re-signing necessary: Option -f
-2009-03-04 18:08:46.385: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-03-04 18:08:46.385: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-03-04 18:08:46.386: debug: Signing zone "sub.example.net."
-2009-03-04 18:08:46.386: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -n 0 -3 1864E1 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-03-04 18:08:46.990: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:08:46.991: debug: Signing completed after 0s.
-2009-03-04 18:08:46.991: debug:
-2009-03-04 18:08:46.991: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:08:46.991: debug: Check RFC5011 status
-2009-03-04 18:08:46.991: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:08:46.991: debug: Check ZSK status
-2009-03-04 18:08:46.991: debug: Re-signing necessary: Option -f
-2009-03-04 18:08:46.991: notice: "example.net.": re-signing triggered: Option -f
-2009-03-04 18:08:46.991: debug: Writing key file "././example.net/dnskey.db"
-2009-03-04 18:08:46.992: debug: Incrementing serial number in file "././example.net/zone.db"
-2009-03-04 18:08:46.992: debug: Signing zone "example.net."
-2009-03-04 18:08:46.993: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 0 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-03-04 18:08:47.149: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:08:47.149: debug: Signing completed after 1s.
-2009-03-04 18:08:47.149: debug:
-2009-03-04 18:08:47.149: notice: end of run: 0 errors occured
-2009-03-04 18:08:59.141: notice: ------------------------------------------------------------
-2009-03-04 18:08:59.141: notice: running ../../dnssec-signer -f -v -v -N named.conf
-2009-03-04 18:08:59.145: debug: parsing zone "sub.example.net." in dir "././sub.example.net"
-2009-03-04 18:08:59.145: debug: Check RFC5011 status
-2009-03-04 18:08:59.145: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-03-04 18:08:59.145: debug: Check KSK status
-2009-03-04 18:08:59.145: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 5d18h13m31s
-2009-03-04 18:08:59.145: debug: Check ZSK status
-2009-03-04 18:08:59.145: debug: Re-signing necessary: Option -f
-2009-03-04 18:08:59.146: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-03-04 18:08:59.146: debug: Writing key file "././sub.example.net/dnskey.db"
-2009-03-04 18:08:59.146: debug: Signing zone "sub.example.net."
-2009-03-04 18:08:59.146: debug: Run cmd "cd ././sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 945691 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-03-04 18:09:00.082: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:09:00.082: debug: Signing completed after 1s.
-2009-03-04 18:09:00.082: debug:
-2009-03-04 18:09:00.083: debug: parsing zone "example.net." in dir "././example.net"
-2009-03-04 18:09:00.083: debug: Check RFC5011 status
-2009-03-04 18:09:00.083: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-03-04 18:09:00.083: debug: Check ZSK status
-2009-03-04 18:09:00.083: debug: Re-signing necessary: Option -f
-2009-03-04 18:09:00.083: notice: "example.net.": re-signing triggered: Option -f
-2009-03-04 18:09:00.083: debug: Writing key file "././example.net/dnskey.db"
-2009-03-04 18:09:00.084: debug: Incrementing serial number in file "././example.net/zone.db"
-2009-03-04 18:09:00.084: debug: Signing zone "example.net."
-2009-03-04 18:09:00.084: debug: Run cmd "cd ././example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-03-04 18:09:00.238: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-03-04 18:09:00.238: debug: Signing completed after 0s.
-2009-03-04 18:09:00.238: debug:
-2009-03-04 18:09:00.238: notice: end of run: 0 errors occured
-2009-06-15 09:58:41.205: notice: ------------------------------------------------------------
-2009-06-15 09:58:41.205: notice: running ../../dnssec-signer -v -v
-2009-06-15 09:58:41.226: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-15 09:58:41.226: debug: Check RFC5011 status
-2009-06-15 09:58:41.226: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-15 09:58:41.226: debug: Check KSK status
-2009-06-15 09:58:41.227: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 15w3d9h3m13s
-2009-06-15 09:58:41.227: debug: Check ZSK status
-2009-06-15 09:58:41.227: debug: Lifetime(259200 +/-150 sec) of active key 32820 exceeded (8948694 sec)
-2009-06-15 09:58:41.227: debug: ->depreciate it
-2009-06-15 09:58:41.227: debug: ->activate published key 49656
-2009-06-15 09:58:41.227: notice: "sub.example.net.": lifetime of zone signing key 32820 exceeded: ZSK rollover done
-2009-06-15 09:58:41.227: debug: New key for publishing needed
-2009-06-15 09:58:41.346: debug: ->creating new key 37135
-2009-06-15 09:58:41.346: info: "sub.example.net.": new key 37135 generated for publishing
-2009-06-15 09:58:41.346: debug: Re-signing necessary: Modfied zone key set
-2009-06-15 09:58:41.346: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-15 09:58:41.346: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-15 09:58:41.346: debug: Signing zone "sub.example.net."
-2009-06-15 09:58:41.346: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 11D7FD -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-15 09:58:41.399: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-15 09:58:41.399: debug: Signing completed after 0s.
-2009-06-15 09:58:41.399: debug:
-2009-06-15 09:58:41.399: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-15 09:58:41.399: debug: Check RFC5011 status
-2009-06-15 09:58:41.399: debug: zone "example.net.": found revoked key (id=1764 exptime=Feb 28 2009 12:31:28); waiting for remove hold down time
-2009-06-15 09:58:41.399: debug: Remove revoked key 1764 which is older than 30 days
-2009-06-15 09:58:41.400: notice: zone "example.net.": removing revoked key 1764
-2009-06-15 09:58:41.400: debug: Check ZSK status
-2009-06-15 09:58:41.400: debug: Lifetime(7776000 +/-150 sec) of active key 4157 exceeded (14547793 sec)
-2009-06-15 09:58:41.400: debug: ->waiting for published key
-2009-06-15 09:58:41.400: notice: "example.net.": lifetime of zone signing key 4157 exceeded since 11w1d9h3m13s: ZSK rollover deferred: waiting for published key
-2009-06-15 09:58:41.400: debug: New key for publishing needed
-2009-06-15 09:58:41.499: debug: ->creating new key 34925
-2009-06-15 09:58:41.499: info: "example.net.": new key 34925 generated for publishing
-2009-06-15 09:58:41.499: debug: Re-signing necessary: Modfied zone key set
-2009-06-15 09:58:41.499: notice: "example.net.": re-signing triggered: Modfied zone key set
-2009-06-15 09:58:41.499: debug: Writing key file "./example.net/dnskey.db"
-2009-06-15 09:58:41.499: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-15 09:58:41.499: debug: Signing zone "example.net."
-2009-06-15 09:58:41.499: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-15 09:58:41.543: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-15 09:58:41.543: debug: Signing completed after 0s.
-2009-06-15 09:58:41.543: debug:
-2009-06-15 09:58:41.543: notice: end of run: 0 errors occured
-2009-06-17 16:36:16.761: notice: ------------------------------------------------------------
-2009-06-17 16:36:16.761: notice: running ../../dnssec-signer -v -v
-2009-06-17 16:36:16.792: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-17 16:36:16.792: debug: Check RFC5011 status
-2009-06-17 16:36:16.792: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-17 16:36:16.792: debug: Check KSK status
-2009-06-17 16:36:16.792: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 15w5d15h40m48s
-2009-06-17 16:36:16.792: debug: Check ZSK status
-2009-06-17 16:36:16.792: debug: Lifetime(390 sec) of depreciated key 32820 exceeded (196655 sec)
-2009-06-17 16:36:16.792: info: "sub.example.net.": old ZSK 32820 removed
-2009-06-17 16:36:16.792: debug: ->remove it
-2009-06-17 16:36:16.792: debug: Re-signing necessary: Modfied zone key set
-2009-06-17 16:36:16.792: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-17 16:36:16.792: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-17 16:36:16.793: debug: Signing zone "sub.example.net."
-2009-06-17 16:36:16.793: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 4214E6 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-17 16:36:16.984: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-17 16:36:16.984: debug: Signing completed after 0s.
-2009-06-17 16:36:16.984: debug:
-2009-06-17 16:36:16.984: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-17 16:36:16.984: debug: Check RFC5011 status
-2009-06-17 16:36:16.984: debug: Check ZSK status
-2009-06-17 16:36:16.984: debug: Lifetime(7776000 +/-150 sec) of active key 4157 exceeded (14744448 sec)
-2009-06-17 16:36:16.984: debug: ->depreciate it
-2009-06-17 16:36:16.984: debug: ->activate published key 34925
-2009-06-17 16:36:16.984: notice: "example.net.": lifetime of zone signing key 4157 exceeded: ZSK rollover done
-2009-06-17 16:36:16.984: debug: Re-signing necessary: Modfied zone key set
-2009-06-17 16:36:16.984: notice: "example.net.": re-signing triggered: Modfied zone key set
-2009-06-17 16:36:16.984: debug: Writing key file "./example.net/dnskey.db"
-2009-06-17 16:36:16.985: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-17 16:36:16.985: debug: Signing zone "example.net."
-2009-06-17 16:36:16.985: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-17 16:36:17.102: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-17 16:36:17.102: debug: Signing completed after 1s.
-2009-06-17 16:36:17.102: debug:
-2009-06-17 16:36:17.102: notice: end of run: 0 errors occured
-2009-06-24 16:33:27.617: notice: ------------------------------------------------------------
-2009-06-24 16:33:27.617: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:33:27.619: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:33:27.619: debug: Check RFC5011 status
-2009-06-24 16:33:27.620: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:33:27.620: debug: Check KSK status
-2009-06-24 16:33:27.620: warning: "sub.example.net.": lifetime of key signing key 18846 exceeded since 16w5d15h37m59s
-2009-06-24 16:33:27.620: debug: Check ZSK status
-2009-06-24 16:33:27.620: debug: Lifetime(259200 +/-150 sec) of active key 49656 exceeded (801286 sec)
-2009-06-24 16:33:27.620: debug: ->depreciate it
-2009-06-24 16:33:27.620: debug: ->activate published key 37135
-2009-06-24 16:33:27.620: notice: "sub.example.net.": lifetime of zone signing key 49656 exceeded: ZSK rollover done
-2009-06-24 16:33:27.620: debug: New key for publishing needed
-2009-06-24 16:33:27.751: debug: ->creating new key 25272
-2009-06-24 16:33:27.751: info: "sub.example.net.": new key 25272 generated for publishing
-2009-06-24 16:33:27.751: debug: Re-signing necessary: Modfied zone key set
-2009-06-24 16:33:27.751: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-24 16:33:27.751: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:33:27.751: debug: Signing zone "sub.example.net."
-2009-06-24 16:33:27.751: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 50C9C8 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:33:27.859: error: "sub.example.net.": signing failed!
-2009-06-24 16:33:27.859: debug: Signing completed after 0s.
-2009-06-24 16:33:27.859: debug:
-2009-06-24 16:33:27.859: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:33:27.859: debug: Check RFC5011 status
-2009-06-24 16:33:27.859: debug: Check ZSK status
-2009-06-24 16:33:27.859: debug: Lifetime(29100 sec) of depreciated key 4157 exceeded (604631 sec)
-2009-06-24 16:33:27.859: info: "example.net.": old ZSK 4157 removed
-2009-06-24 16:33:27.860: debug: ->remove it
-2009-06-24 16:33:27.860: debug: Re-signing necessary: Modfied zone key set
-2009-06-24 16:33:27.860: notice: "example.net.": re-signing triggered: Modfied zone key set
-2009-06-24 16:33:27.860: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 16:33:27.860: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 16:33:27.860: debug: Signing zone "example.net."
-2009-06-24 16:33:27.860: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-24 16:33:27.966: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:33:27.966: debug: Signing completed after 0s.
-2009-06-24 16:33:27.966: debug:
-2009-06-24 16:33:27.966: notice: end of run: 1 error occured
-2009-06-24 16:42:06.709: notice: ------------------------------------------------------------
-2009-06-24 16:42:06.709: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:42:06.711: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:42:06.711: debug: Check RFC5011 status
-2009-06-24 16:42:06.711: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:42:06.711: debug: Check KSK status
-2009-06-24 16:42:06.711: debug: No active KSK found: generate new one
-2009-06-24 16:42:06.855: info: "sub.example.net.": generated new KSK 48516
-2009-06-24 16:42:06.855: debug: Check ZSK status
-2009-06-24 16:42:06.855: debug: No active ZSK found: generate new one
-2009-06-24 16:42:06.883: info: "sub.example.net.": generated new ZSK 33383
-2009-06-24 16:42:06.883: debug: Re-signing necessary: Modfied zone key set
-2009-06-24 16:42:06.883: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-24 16:42:06.883: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:42:06.883: debug: Signing zone "sub.example.net."
-2009-06-24 16:42:06.883: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:42:06.905: error: "sub.example.net.": signing failed!
-2009-06-24 16:42:06.905: debug: Signing completed after 0s.
-2009-06-24 16:42:06.905: debug:
-2009-06-24 16:42:06.905: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:42:06.905: debug: Check RFC5011 status
-2009-06-24 16:42:06.905: debug: Check ZSK status
-2009-06-24 16:42:06.905: debug: Re-signing not necessary!
-2009-06-24 16:42:06.905: debug: Check if there is a parent file to copy
-2009-06-24 16:42:06.905: debug:
-2009-06-24 16:42:06.905: notice: end of run: 1 error occured
-2009-06-24 16:42:31.402: notice: ------------------------------------------------------------
-2009-06-24 16:42:31.402: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:42:31.404: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:42:31.404: debug: Check RFC5011 status
-2009-06-24 16:42:31.404: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:42:31.404: debug: Check KSK status
-2009-06-24 16:42:31.404: debug: Check ZSK status
-2009-06-24 16:42:31.404: debug: Re-signing necessary: Modified keys
-2009-06-24 16:42:31.405: notice: "sub.example.net.": re-signing triggered: Modified keys
-2009-06-24 16:42:31.405: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:42:31.405: debug: Signing zone "sub.example.net."
-2009-06-24 16:42:31.405: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:42:31.449: error: "sub.example.net.": signing failed!
-2009-06-24 16:42:31.450: debug: Signing completed after 0s.
-2009-06-24 16:42:31.450: debug:
-2009-06-24 16:42:31.450: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:42:31.450: debug: Check RFC5011 status
-2009-06-24 16:42:31.450: debug: Check ZSK status
-2009-06-24 16:42:31.450: debug: Re-signing not necessary!
-2009-06-24 16:42:31.450: debug: Check if there is a parent file to copy
-2009-06-24 16:42:31.450: debug:
-2009-06-24 16:42:31.450: notice: end of run: 1 error occured
-2009-06-24 16:42:48.193: notice: ------------------------------------------------------------
-2009-06-24 16:42:48.193: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:42:48.195: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:42:48.195: debug: Check RFC5011 status
-2009-06-24 16:42:48.195: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:42:48.195: debug: Check KSK status
-2009-06-24 16:42:48.195: debug: Check ZSK status
-2009-06-24 16:42:48.195: debug: Re-signing necessary: Modified keys
-2009-06-24 16:42:48.195: notice: "sub.example.net.": re-signing triggered: Modified keys
-2009-06-24 16:42:48.195: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:42:48.195: debug: Signing zone "sub.example.net."
-2009-06-24 16:42:48.195: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 F46ADF -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:42:48.212: error: "sub.example.net.": signing failed!
-2009-06-24 16:42:48.212: debug: Signing completed after 0s.
-2009-06-24 16:42:48.212: debug:
-2009-06-24 16:42:48.212: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:42:48.212: debug: Check RFC5011 status
-2009-06-24 16:42:48.212: debug: Check ZSK status
-2009-06-24 16:42:48.212: debug: Re-signing not necessary!
-2009-06-24 16:42:48.212: debug: Check if there is a parent file to copy
-2009-06-24 16:42:48.212: debug:
-2009-06-24 16:42:48.212: notice: end of run: 1 error occured
-2009-06-24 16:44:22.959: notice: ------------------------------------------------------------
-2009-06-24 16:44:22.959: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:44:22.961: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:44:22.961: debug: Check RFC5011 status
-2009-06-24 16:44:22.961: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:44:22.961: debug: Check KSK status
-2009-06-24 16:44:22.961: debug: Check ZSK status
-2009-06-24 16:44:22.961: debug: No active ZSK found: generate new one
-2009-06-24 16:44:23.008: info: "sub.example.net.": generated new ZSK 14600
-2009-06-24 16:44:23.008: debug: Re-signing necessary: Modfied zone key set
-2009-06-24 16:44:23.008: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-24 16:44:23.009: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:44:23.009: debug: Signing zone "sub.example.net."
-2009-06-24 16:44:23.009: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 86BF2F -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:44:23.040: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:44:23.040: debug: Signing completed after 0s.
-2009-06-24 16:44:23.040: debug:
-2009-06-24 16:44:23.040: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:44:23.040: debug: Check RFC5011 status
-2009-06-24 16:44:23.040: debug: Check ZSK status
-2009-06-24 16:44:23.040: debug: Re-signing not necessary!
-2009-06-24 16:44:23.040: debug: Check if there is a parent file to copy
-2009-06-24 16:44:23.040: debug:
-2009-06-24 16:44:23.040: notice: end of run: 0 errors occured
-2009-06-24 16:50:36.189: notice: ------------------------------------------------------------
-2009-06-24 16:50:36.189: notice: running ../../dnssec-signer -v -v
-2009-06-24 16:50:36.191: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:50:36.191: debug: Check RFC5011 status
-2009-06-24 16:50:36.191: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:50:36.191: debug: Check KSK status
-2009-06-24 16:50:36.192: debug: Check ZSK status
-2009-06-24 16:50:36.192: debug: Re-signing not necessary!
-2009-06-24 16:50:36.192: debug: Check if there is a parent file to copy
-2009-06-24 16:50:36.192: debug:
-2009-06-24 16:50:36.192: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:50:36.192: debug: Check RFC5011 status
-2009-06-24 16:50:36.192: debug: Check ZSK status
-2009-06-24 16:50:36.193: debug: Re-signing not necessary!
-2009-06-24 16:50:36.193: debug: Check if there is a parent file to copy
-2009-06-24 16:50:36.193: debug:
-2009-06-24 16:50:36.193: notice: end of run: 0 errors occured
-2009-06-24 16:50:42.877: notice: ------------------------------------------------------------
-2009-06-24 16:50:42.877: notice: running ../../dnssec-signer -v -v -f
-2009-06-24 16:50:42.879: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:50:42.879: debug: Check RFC5011 status
-2009-06-24 16:50:42.879: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:50:42.879: debug: Check KSK status
-2009-06-24 16:50:42.879: debug: Check ZSK status
-2009-06-24 16:50:42.879: debug: Re-signing necessary: Option -f
-2009-06-24 16:50:42.879: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-24 16:50:42.879: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:50:42.879: debug: Signing zone "sub.example.net."
-2009-06-24 16:50:42.879: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 FB37DB -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:50:42.932: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:50:42.932: debug: Signing completed after 0s.
-2009-06-24 16:50:42.932: debug:
-2009-06-24 16:50:42.932: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:50:42.932: debug: Check RFC5011 status
-2009-06-24 16:50:42.932: debug: Check ZSK status
-2009-06-24 16:50:42.932: debug: Re-signing necessary: Option -f
-2009-06-24 16:50:42.932: notice: "example.net.": re-signing triggered: Option -f
-2009-06-24 16:50:42.932: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 16:50:42.933: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 16:50:42.933: debug: Signing zone "example.net."
-2009-06-24 16:50:42.933: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-24 16:50:42.978: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:50:42.978: debug: Signing completed after 0s.
-2009-06-24 16:50:42.978: debug:
-2009-06-24 16:50:42.979: notice: end of run: 0 errors occured
-2009-06-24 16:50:51.923: notice: ------------------------------------------------------------
-2009-06-24 16:50:51.923: notice: running ../../dnssec-signer -v -v -f
-2009-06-24 16:50:51.924: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:50:51.924: debug: Check RFC5011 status
-2009-06-24 16:50:51.924: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:50:51.924: debug: Check KSK status
-2009-06-24 16:50:51.924: debug: Check ZSK status
-2009-06-24 16:50:51.925: debug: Re-signing necessary: Option -f
-2009-06-24 16:50:51.925: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-24 16:50:51.925: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:50:51.925: debug: Signing zone "sub.example.net."
-2009-06-24 16:50:51.925: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 E830EA -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:50:51.972: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:50:51.973: debug: Signing completed after 0s.
-2009-06-24 16:50:51.973: debug:
-2009-06-24 16:50:51.973: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:50:51.973: debug: Check RFC5011 status
-2009-06-24 16:50:51.973: debug: Check ZSK status
-2009-06-24 16:50:51.973: debug: Re-signing necessary: Option -f
-2009-06-24 16:50:51.973: notice: "example.net.": re-signing triggered: Option -f
-2009-06-24 16:50:51.973: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 16:50:51.973: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 16:50:51.973: debug: Signing zone "example.net."
-2009-06-24 16:50:51.973: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-24 16:50:52.017: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:50:52.017: debug: Signing completed after 1s.
-2009-06-24 16:50:52.017: debug:
-2009-06-24 16:50:52.017: notice: end of run: 0 errors occured
-2009-06-24 16:51:19.914: notice: ------------------------------------------------------------
-2009-06-24 16:51:19.914: notice: running ../../dnssec-signer -v -v -f
-2009-06-24 16:51:19.916: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:51:19.916: debug: Check RFC5011 status
-2009-06-24 16:51:19.916: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:51:19.916: debug: Check KSK status
-2009-06-24 16:51:19.916: debug: Check ZSK status
-2009-06-24 16:51:19.916: debug: Re-signing necessary: Option -f
-2009-06-24 16:51:19.916: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-24 16:51:19.916: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:51:19.917: debug: Signing zone "sub.example.net."
-2009-06-24 16:51:19.917: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 8DBC26 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private"
-2009-06-24 16:51:19.969: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:51:19.969: debug: Signing completed after 0s.
-2009-06-24 16:51:19.969: debug:
-2009-06-24 16:51:19.969: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:51:19.969: debug: Check RFC5011 status
-2009-06-24 16:51:19.969: debug: Check ZSK status
-2009-06-24 16:51:19.969: debug: Re-signing necessary: Option -f
-2009-06-24 16:51:19.969: notice: "example.net.": re-signing triggered: Option -f
-2009-06-24 16:51:19.969: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 16:51:19.969: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 16:51:19.969: debug: Signing zone "example.net."
-2009-06-24 16:51:19.969: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private"
-2009-06-24 16:51:20.018: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 16:51:20.018: debug: Signing completed after 1s.
-2009-06-24 16:51:20.018: debug:
-2009-06-24 16:51:20.018: notice: end of run: 0 errors occured
-2009-06-24 16:55:38.094: notice: ------------------------------------------------------------
-2009-06-24 16:55:38.094: notice: running ../../dnssec-signer -v -v -f
-2009-06-24 16:55:38.096: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 16:55:38.096: debug: Check RFC5011 status
-2009-06-24 16:55:38.096: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 16:55:38.096: debug: Check KSK status
-2009-06-24 16:55:38.096: debug: Check ZSK status
-2009-06-24 16:55:38.096: debug: Re-signing necessary: Option -f
-2009-06-24 16:55:38.096: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-24 16:55:38.096: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 16:55:38.097: debug: Signing zone "sub.example.net."
-2009-06-24 16:55:38.097: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 69AB8E -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-24 16:55:38.144: debug: Cmd dnssec-signzone return: "Verifying the zone using the following algorithms: NSEC3RSASHA1."
-2009-06-24 16:55:38.144: debug: Signing completed after 0s.
-2009-06-24 16:55:38.144: debug:
-2009-06-24 16:55:38.144: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 16:55:38.144: debug: Check RFC5011 status
-2009-06-24 16:55:38.144: debug: Check ZSK status
-2009-06-24 16:55:38.144: debug: Re-signing necessary: Option -f
-2009-06-24 16:55:38.144: notice: "example.net.": re-signing triggered: Option -f
-2009-06-24 16:55:38.144: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 16:55:38.144: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 16:55:38.144: debug: Signing zone "example.net."
-2009-06-24 16:55:38.144: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
-2009-06-24 16:55:38.182: debug: Cmd dnssec-signzone return: "Verifying the zone using the following algorithms: RSASHA1."
-2009-06-24 16:55:38.182: debug: Signing completed after 0s.
-2009-06-24 16:55:38.182: debug:
-2009-06-24 16:55:38.182: notice: end of run: 0 errors occured
-2009-06-24 17:12:06.145: notice: ------------------------------------------------------------
-2009-06-24 17:12:06.145: notice: running ../../dnssec-signer -v -v -f
-2009-06-24 17:12:06.147: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-24 17:12:06.147: debug: Check RFC5011 status
-2009-06-24 17:12:06.147: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-24 17:12:06.147: debug: Check KSK status
-2009-06-24 17:12:06.147: debug: Check ZSK status
-2009-06-24 17:12:06.147: debug: Re-signing necessary: Option -f
-2009-06-24 17:12:06.147: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-24 17:12:06.147: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-24 17:12:06.147: debug: Signing zone "sub.example.net."
-2009-06-24 17:12:06.147: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 589BFC -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-24 17:12:06.204: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 17:12:06.204: debug: Signing completed after 0s.
-2009-06-24 17:12:06.204: debug:
-2009-06-24 17:12:06.204: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-24 17:12:06.204: debug: Check RFC5011 status
-2009-06-24 17:12:06.204: debug: Check ZSK status
-2009-06-24 17:12:06.204: debug: Re-signing necessary: Option -f
-2009-06-24 17:12:06.205: notice: "example.net.": re-signing triggered: Option -f
-2009-06-24 17:12:06.205: debug: Writing key file "./example.net/dnskey.db"
-2009-06-24 17:12:06.205: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-24 17:12:06.205: debug: Signing zone "example.net."
-2009-06-24 17:12:06.205: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
-2009-06-24 17:12:06.259: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-24 17:12:06.259: debug: Signing completed after 0s.
-2009-06-24 17:12:06.259: debug:
-2009-06-24 17:12:06.259: notice: end of run: 0 errors occured
-2009-06-30 11:35:09.298: notice: ------------------------------------------------------------
-2009-06-30 11:35:09.298: notice: running ../../dnssec-signer -v -v
-2009-06-30 11:35:09.326: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-30 11:35:09.326: debug: Check RFC5011 status
-2009-06-30 11:35:09.326: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-30 11:35:09.326: debug: Check KSK status
-2009-06-30 11:35:09.326: debug: Check ZSK status
-2009-06-30 11:35:09.326: debug: Lifetime(259200 +/-150 sec) of active key 14600 exceeded (499847 sec)
-2009-06-30 11:35:09.326: debug: ->waiting for published key
-2009-06-30 11:35:09.326: notice: "sub.example.net.": lifetime of zone signing key 14600 exceeded since 2d18h50m47s: ZSK rollover deferred: waiting for published key
-2009-06-30 11:35:09.326: debug: New key for publishing needed
-2009-06-30 11:35:09.482: debug: ->creating new key 32345
-2009-06-30 11:35:09.482: info: "sub.example.net.": new key 32345 generated for publishing
-2009-06-30 11:35:09.482: debug: Re-signing necessary: Modfied zone key set
-2009-06-30 11:35:09.483: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-30 11:35:09.483: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-30 11:35:09.483: debug: Signing zone "sub.example.net."
-2009-06-30 11:35:09.483: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 E84B0F -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-30 11:35:09.838: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 11:35:09.838: debug: Signing completed after 0s.
-2009-06-30 11:35:09.838: debug:
-2009-06-30 11:35:09.838: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-30 11:35:09.838: debug: Check RFC5011 status
-2009-06-30 11:35:09.838: debug: Check ZSK status
-2009-06-30 11:35:09.838: debug: New key for publishing needed
-2009-06-30 11:35:09.896: debug: ->creating new key 48089
-2009-06-30 11:35:09.896: info: "example.net.": new key 48089 generated for publishing
-2009-06-30 11:35:09.896: debug: Re-signing necessary: Modfied zone key set
-2009-06-30 11:35:09.897: notice: "example.net.": re-signing triggered: Modfied zone key set
-2009-06-30 11:35:09.897: debug: Writing key file "./example.net/dnskey.db"
-2009-06-30 11:35:09.897: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-30 11:35:09.897: debug: Signing zone "example.net."
-2009-06-30 11:35:09.897: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
-2009-06-30 11:35:09.997: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 11:35:09.997: debug: Signing completed after 0s.
-2009-06-30 11:35:09.997: debug:
-2009-06-30 11:35:09.997: notice: end of run: 0 errors occured
-2009-06-30 12:01:53.878: notice: ------------------------------------------------------------
-2009-06-30 12:01:53.878: notice: running ../../dnssec-signer -v -v
-2009-06-30 12:01:53.880: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-30 12:01:53.881: debug: Check RFC5011 status
-2009-06-30 12:01:53.881: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-30 12:01:53.881: debug: Check KSK status
-2009-06-30 12:01:53.881: debug: Check ZSK status
-2009-06-30 12:01:53.881: debug: Lifetime(259200 +/-150 sec) of active key 14600 exceeded (501451 sec)
-2009-06-30 12:01:53.881: debug: ->waiting for published key
-2009-06-30 12:01:53.881: notice: "sub.example.net.": lifetime of zone signing key 14600 exceeded since 2d19h17m31s: ZSK rollover deferred: waiting for published key
-2009-06-30 12:01:53.881: debug: Re-signing not necessary!
-2009-06-30 12:01:53.881: debug: Check if there is a parent file to copy
-2009-06-30 12:01:53.881: debug:
-2009-06-30 12:01:53.881: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-30 12:01:53.881: debug: Check RFC5011 status
-2009-06-30 12:01:53.881: debug: Check ZSK status
-2009-06-30 12:01:53.881: debug: Re-signing not necessary!
-2009-06-30 12:01:53.881: debug: Check if there is a parent file to copy
-2009-06-30 12:01:53.881: debug:
-2009-06-30 12:01:53.881: notice: end of run: 0 errors occured
-2009-06-30 12:02:05.490: notice: ------------------------------------------------------------
-2009-06-30 12:02:05.490: notice: running ../../dnssec-signer -f -v -v
-2009-06-30 12:02:05.492: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-30 12:02:05.492: debug: Check RFC5011 status
-2009-06-30 12:02:05.492: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-30 12:02:05.492: debug: Check KSK status
-2009-06-30 12:02:05.492: debug: Check ZSK status
-2009-06-30 12:02:05.492: debug: Lifetime(259200 +/-150 sec) of active key 14600 exceeded (501463 sec)
-2009-06-30 12:02:05.492: debug: ->waiting for published key
-2009-06-30 12:02:05.492: notice: "sub.example.net.": lifetime of zone signing key 14600 exceeded since 2d19h17m43s: ZSK rollover deferred: waiting for published key
-2009-06-30 12:02:05.492: debug: Re-signing necessary: Option -f
-2009-06-30 12:02:05.492: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-30 12:02:05.492: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-30 12:02:05.492: debug: Signing zone "sub.example.net."
-2009-06-30 12:02:05.492: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 50B303 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-30 12:02:05.543: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 12:02:05.543: debug: Signing completed after 0s.
-2009-06-30 12:02:05.543: debug:
-2009-06-30 12:02:05.543: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-30 12:02:05.543: debug: Check RFC5011 status
-2009-06-30 12:02:05.543: debug: Check ZSK status
-2009-06-30 12:02:05.543: debug: Re-signing necessary: Option -f
-2009-06-30 12:02:05.543: notice: "example.net.": re-signing triggered: Option -f
-2009-06-30 12:02:05.543: debug: Writing key file "./example.net/dnskey.db"
-2009-06-30 12:02:05.544: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-30 12:02:05.544: debug: Signing zone "example.net."
-2009-06-30 12:02:05.544: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
-2009-06-30 12:02:05.602: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 12:02:05.602: debug: Signing completed after 0s.
-2009-06-30 12:02:05.602: debug:
-2009-06-30 12:02:05.602: notice: end of run: 0 errors occured
-2009-06-30 13:02:04.436: notice: ------------------------------------------------------------
-2009-06-30 13:02:04.436: notice: running ../../dnssec-signer -v -v
-2009-06-30 13:02:04.438: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-30 13:02:04.438: debug: Check RFC5011 status
-2009-06-30 13:02:04.438: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-30 13:02:04.438: debug: Check KSK status
-2009-06-30 13:02:04.438: debug: Check ZSK status
-2009-06-30 13:02:04.438: debug: Lifetime(259200 +/-150 sec) of active key 14600 exceeded (505062 sec)
-2009-06-30 13:02:04.438: debug: ->depreciate it
-2009-06-30 13:02:04.439: debug: ->activate published key 32345
-2009-06-30 13:02:04.439: notice: "sub.example.net.": lifetime of zone signing key 14600 exceeded: ZSK rollover done
-2009-06-30 13:02:04.439: debug: Re-signing necessary: Modfied zone key set
-2009-06-30 13:02:04.439: notice: "sub.example.net.": re-signing triggered: Modfied zone key set
-2009-06-30 13:02:04.439: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-30 13:02:04.439: debug: Signing zone "sub.example.net."
-2009-06-30 13:02:04.439: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 0140D2 -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-30 13:02:04.491: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 13:02:04.491: debug: Signing completed after 0s.
-2009-06-30 13:02:04.491: debug:
-2009-06-30 13:02:04.491: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-30 13:02:04.491: debug: Check RFC5011 status
-2009-06-30 13:02:04.491: debug: Check ZSK status
-2009-06-30 13:02:04.491: debug: Re-signing not necessary!
-2009-06-30 13:02:04.491: debug: Check if there is a parent file to copy
-2009-06-30 13:02:04.491: debug:
-2009-06-30 13:02:04.491: notice: end of run: 0 errors occured
-2009-06-30 13:02:21.019: notice: ------------------------------------------------------------
-2009-06-30 13:02:21.019: notice: running ../../dnssec-signer -f -v -v
-2009-06-30 13:02:21.021: debug: parsing zone "sub.example.net." in dir "./sub.example.net"
-2009-06-30 13:02:21.021: debug: Check RFC5011 status
-2009-06-30 13:02:21.021: debug: ->not a rfc5011 zone, looking for a regular ksk rollover
-2009-06-30 13:02:21.021: debug: Check KSK status
-2009-06-30 13:02:21.021: debug: Check ZSK status
-2009-06-30 13:02:21.022: debug: Re-signing necessary: Option -f
-2009-06-30 13:02:21.022: notice: "sub.example.net.": re-signing triggered: Option -f
-2009-06-30 13:02:21.022: debug: Writing key file "./sub.example.net/dnskey.db"
-2009-06-30 13:02:21.022: debug: Signing zone "sub.example.net."
-2009-06-30 13:02:21.022: debug: Run cmd "cd ./sub.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 86F43F -g -p -d ../keysets -o sub.example.net. -e +172800 -l dlv.trusted-keys.de -N unixtime zone.db K*.private 2>&1"
-2009-06-30 13:02:21.070: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 13:02:21.070: debug: Signing completed after 0s.
-2009-06-30 13:02:21.070: debug:
-2009-06-30 13:02:21.070: debug: parsing zone "example.net." in dir "./example.net"
-2009-06-30 13:02:21.070: debug: Check RFC5011 status
-2009-06-30 13:02:21.070: debug: Check ZSK status
-2009-06-30 13:02:21.070: debug: Re-signing necessary: Option -f
-2009-06-30 13:02:21.070: notice: "example.net.": re-signing triggered: Option -f
-2009-06-30 13:02:21.071: debug: Writing key file "./example.net/dnskey.db"
-2009-06-30 13:02:21.071: debug: Incrementing serial number in file "./example.net/zone.db"
-2009-06-30 13:02:21.071: debug: Signing zone "example.net."
-2009-06-30 13:02:21.071: debug: Run cmd "cd ./example.net; /usr/local/sbin/dnssec-signzone -n 1 -g -p -d ../keysets -o example.net. -e +518400 zone.db K*.private 2>&1"
-2009-06-30 13:02:21.121: debug: Cmd dnssec-signzone return: "zone.db.signed"
-2009-06-30 13:02:21.121: debug: Signing completed after 0s.
-2009-06-30 13:02:21.121: debug:
-2009-06-30 13:02:21.121: notice: end of run: 0 errors occured