DNSSEC-Provisioning / music

Multi-Signer Controller (MuSiC)
6 stars 5 forks source link

PostCondition after adding CDS is not robust. #136

Closed johanix closed 1 year ago

johanix commented 2 years ago

2022/03/27 20:00:50 Verify Publication of CDS: there are KSKs at the signers with the following keytags: [] 2022/03/27 20:00:50 DDNS: FetchRRset: signer: BRAVO zone: bravo.music.dnslab. fqdn: bravo.music.dnslab. rrtype: CDS 2022/03/27 20:00:50 DDNS: Accessing signer BRAVO via UDP. This is a debugging mechanism only 2022/03/27 20:00:50 Length of CDS answer from BRAVO:53: 0 RRs 2022/03/27 20:00:50 DDNS: FetchRRset: signer: BRAVO zone: bravo.music.dnslab. fqdn: bravo.music.dnslab. rrtype: CDNSKEY 2022/03/27 20:00:50 DDNS: Accessing signer BRAVO via UDP. This is a debugging mechanism only 2022/03/27 20:00:50 Length of CDNSKEY answer from BRAVO:53: 0 RRs This is bravo.music.dnslab.StateTransition(dnskeys-synced-->cds-added) in process add-signer 2022/03/27 20:00:50 Zone bravo.music.dnslab. transitioned from dnskeys-synced to cds-added in process add-signer

romu42 commented 2 years ago

The code is robust, but doesn't seem to respect the changes to sync KSK/CSK as well as ZSK.