This is a SIMPLIFIED procedure how to manage key rollovers. When rolling over ZSK you must also include overlap time period.
####ZSK###
Take a look at the existing keys in softhsm
$ pkcs11-list
Enter PIN:| $ = jQuery | |
| queues = {} | |
| running = false | |
| queue = (name) -> | |
| name = 'default' if name is true | |
| queues[name] or= [] | |
| next = (name) -> |
This is a SIMPLIFIED procedure how to manage key rollovers. When rolling over ZSK you must also include overlap time period.
####ZSK###
Take a look at the existing keys in softhsm
$ pkcs11-list
Enter PIN:This is a guide how to setup dnssec with Bind 9.9 (inline signing) and with softhsm keystore. Setup was done on Debian Squeeze.
Based on https://deepthought.isc.org/article/AA-00659/116/BIND-9.9.0-Administrator-Reference-Manual.html
###Build Softhsm###
$ wget http://www.opendnssec.org/files/source/softhsm-1.3.3.tar.gz
$ cd softhsm-1.3.3