DNSSEC key and zone management software
Issues reported fixed by upstream (same as 2.1.9): - OPENDNSSEC-955: Prevent concurrency between certain valid PKCS#11 HSM operations to avoid some keys to be (transiently) unavailable. - OPENDNSSEC-956: Harden signing procedure to still sign zones for which there are unused keys specified in the zone which are unavailable. Issues newly reported fixed: - OPENDNSSEC-957: Fix exit code signer daemon to not always report failure. - OPENDNSSEC-958: Fix immediate resalting after migration from 1.4. - OPENDNSSEC-959: Emit warning on ods-kaspcheck for NSEC iteration count that is deemed too high. - SUPPORT-265: Resolve conflict when deleting keys from HSM whilst also performing step in key roll process. Typically a message “key_data_update failed” is present in logs. |
||
|---|---|---|
| .gitignore | ||
| conf.xml | ||
| ods-enforcerd.init | ||
| ods-enforcerd.service | ||
| ods-signerd.init | ||
| ods-signerd.service | ||
| ods.sysconfig | ||
| opendnssec-1.4.5-serial0.patch | ||
| opendnssec-1.4.6-extract.patch | ||
| opendnssec-1.4.7-extract.patch | ||
| opendnssec-1.4.13-openssl1.1.patch | ||
| opendnssec-2.1.sqlite_convert.sql | ||
| opendnssec-2.1.sqlite_rpmversion.sql | ||
| opendnssec-LICENSE | ||
| opendnssec.cron | ||
| opendnssec.spec | ||
| sources | ||
| tmpfiles-opendnssec.conf | ||