[Dnssec-deployment] Signatures in KG zone have premature start times
cet1 at cam.ac.uk
Fri Feb 25 10:42:04 EST 2011
FYI, the "kg" problem got fixed yesterday.
Assuming that the SOA serials were time_t values for creation of
the zone version, the RRSIG start times were being consistently set
1 hour earlier (a familiar algorithm). But both were several hours
in the future w.r.t. the rest of the world. (The data seems to be
not inconsistent with Stephane's conjecture of 6 hours.)
If there are any KG administrators listening, I am sure it would be
helpful to the rest of the DNSSEC deployment community if they told
us what happened.
Chris Thompson University of Cambridge Computing Service,
Email: cet1 at ucs.cam.ac.uk New Museums Site, Cambridge CB2 3QH,
Phone: +44 1223 334715 United Kingdom.
More information about the Dnssec-deployment