On Mon Nov 28 21:22:11 2016, daniel.salzman(a)nic.cz wrote:
Hi,
As you are running 2.3.1 version, you must create an empty configuration for
the module:
mod-online-sign:
- id: default
zone:
- domain: tregon-grifon.swordarmor.fr
module: [mod-synth-record/tregon-grifon, mod-online-sign/default]
...
The second problem is that this module hasn't been upgraded to the new
dnssec
configuration. So you must utilize keymgr in the legacy mode:
$ keymgr -l init
$ keymgr -l zone add tregon-grifon.swordarmor.fr
$ keymgr -l zone key generate tregon-grifon.swordarmor.fr algorithm
ecdsap256sha256 size 256
Then the online signing should work.
I'm sorry for these complications.
Daniel
Hi,
Thanks for your explanations, it works :)
I wrote a little article about this (in french, because I’m from .fr) to
remember myself how to do this.
https://www.swordarmor.fr/knot-reverse-automatique-et-dnssec.html
Sorry for the delay,
--
alarig