Please migrate to a newer version of Knot (2.6.0 or 2.5.5) as with this version
it is much easier to configure DNSSEC signing without manual keymgr assistance.
To be honest, I'm no longer able to use such an old version of Knot :-)


On 09/29/2017 09:39 AM, josef Karliak wrote:

  I maybe missed something. I created kasp direcotry, added knot as a owner.
  In the kasp directory (/var/lib/knot/kasp) runned commands:
keymgr init
keymgr zone add domena.cz policy none
keymgr zone key generate domena.cz algorithm rsasha256 size 2048 ksk

Cannot retrieve policy from KASP (not found).

  Did I missed something ?
  Thanks and best regards

