2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-30 14:07:59 +00:00

Merge branch '2027-update-managed-keys-log-messages' into 'main'

Resolve "Slightly misleading diagnostic when revoked key is removed from managed-keys zone"

Closes #2027

See merge request isc-projects/bind9!3934
This commit is contained in:
Mark Andrews
2020-08-11 00:54:39 +00:00
2 changed files with 14 additions and 9 deletions

View File

@@ -1,3 +1,6 @@
5487. [cleanup] Update managed keys log messages to be less confusing.
[GL #2027]
5486. [func] Add 'rndc dnssec -checkds' command to tell named 5486. [func] Add 'rndc dnssec -checkds' command to tell named
that the DS record has been published in the parent. that the DS record has been published in the parent.
[GL #1613] [GL #1613]

View File

@@ -10252,9 +10252,9 @@ anchors_done:
} else if (keydata.addhd > now) { } else if (keydata.addhd > now) {
dnssec_log(zone, ISC_LOG_INFO, dnssec_log(zone, ISC_LOG_INFO,
"Pending key %d for zone %s " "Pending key %d for zone %s "
"unexpectedly missing " "unexpectedly missing from DNSKEY "
"restarting 30-day acceptance " "RRset: restarting 30-day "
"timer", "acceptance timer",
keytag, namebuf); keytag, namebuf);
if (keydata.addhd < now + dns_zone_mkey_month) { if (keydata.addhd < now + dns_zone_mkey_month) {
keydata.addhd = now + keydata.addhd = now +
@@ -10264,15 +10264,17 @@ anchors_done:
} else if (keydata.removehd == 0) { } else if (keydata.removehd == 0) {
dnssec_log(zone, ISC_LOG_INFO, dnssec_log(zone, ISC_LOG_INFO,
"Active key %d for zone %s " "Active key %d for zone %s "
"unexpectedly missing", "unexpectedly missing from DNSKEY "
"RRset",
keytag, namebuf); keytag, namebuf);
keydata.refresh = now + dns_zone_mkey_hour; keydata.refresh = now + dns_zone_mkey_hour;
} else if (keydata.removehd <= now) { } else if (keydata.removehd <= now) {
deletekey = true; deletekey = true;
dnssec_log(zone, ISC_LOG_INFO, dnssec_log(
"Revoked key %d for zone %s " zone, ISC_LOG_INFO,
"missing: deleting from " "Revoked key %d for zone %s no longer "
"managed keys database", "present in DNSKEY RRset: deleting "
"from managed keys database",
keytag, namebuf); keytag, namebuf);
} else { } else {
keydata.refresh = refresh_time(kfetch, false); keydata.refresh = refresh_time(kfetch, false);