2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-29 21:47:59 +00:00

Merge branch '2027-update-managed-keys-log-messages' into 'main'

Resolve "Slightly misleading diagnostic when revoked key is removed from managed-keys zone"

Closes #2027

See merge request isc-projects/bind9!3934
This commit is contained in:
Mark Andrews 2020-08-11 00:54:39 +00:00
commit f9537a6f2a
2 changed files with 14 additions and 9 deletions

View File

@ -1,3 +1,6 @@
5487. [cleanup] Update managed keys log messages to be less confusing.
[GL #2027]
5486. [func] Add 'rndc dnssec -checkds' command to tell named
that the DS record has been published in the parent.
[GL #1613]

View File

@ -10252,9 +10252,9 @@ anchors_done:
} else if (keydata.addhd > now) {
dnssec_log(zone, ISC_LOG_INFO,
"Pending key %d for zone %s "
"unexpectedly missing "
"restarting 30-day acceptance "
"timer",
"unexpectedly missing from DNSKEY "
"RRset: restarting 30-day "
"acceptance timer",
keytag, namebuf);
if (keydata.addhd < now + dns_zone_mkey_month) {
keydata.addhd = now +
@ -10264,16 +10264,18 @@ anchors_done:
} else if (keydata.removehd == 0) {
dnssec_log(zone, ISC_LOG_INFO,
"Active key %d for zone %s "
"unexpectedly missing",
"unexpectedly missing from DNSKEY "
"RRset",
keytag, namebuf);
keydata.refresh = now + dns_zone_mkey_hour;
} else if (keydata.removehd <= now) {
deletekey = true;
dnssec_log(zone, ISC_LOG_INFO,
"Revoked key %d for zone %s "
"missing: deleting from "
"managed keys database",
keytag, namebuf);
dnssec_log(
zone, ISC_LOG_INFO,
"Revoked key %d for zone %s no longer "
"present in DNSKEY RRset: deleting "
"from managed keys database",
keytag, namebuf);
} else {
keydata.refresh = refresh_time(kfetch, false);
}