On 1 Dec 2025, at 14:13, Einar Bjarni Halldórsson via
knot-dns-users <knot-dns-users(a)lists.nic.cz> wrote:
I just ran `knotc zone-ksk-submitted` on three different servers, all with zones
migrating from RSASHA256 to ECDSAP256SHA256
and I’m not seeing the error (yet).
All three sets of servers are running Knot 3.5.2 on FreeBSD 14.3.
Either the error happens later, when the old keys are purged, or the error has been fixed
between 3.5.0 and 3.5.2.
I did upgrade a server to 3.5.2 and saw the error, but that was after rollover had
finished on the primary when it was
running 3.5.0.
I’m going to attempt to downgrade a server to 3.5.0 and perform an algorithm rollover and
sync. If the error
appears, we’ll know it’s in the rollover itself where some state is produced which causes
the error.
I just setup a test environment, running 3.5.0, but I can’t reproduce the error.
There must have been some legacy rot on the signers which caused it.
.einar