Hi Andrew,
Thanks for the report, it is a bug in knsupdate. There is an incorrect check for KEY type
in keyfile processing.
We will fix it in the 1.6.2 release.
A quick workaround would be a replacement of KEY type with a DNSKEY in keyfiles.
Dan
On 02/04/2015 11:41 AM, Andrew Stevenson wrote:
Hi,
I am trying to use nsupdate from knot 1.6.1. I have generated key files using
dnssec-keygen from BIND 9.9.5. i.e.
dnssec-keygen -a HMAC-MD5 -b 256 -n HOST -C
host.example.com
Whenever I try to use the files with nsupdate -k <file> though I get:
; Error: failed to read key file: public key file is invalid
I have also tried without the “-C” to dnssec-keygen.
Are there different flags I need? Or does someone have an example of the file format
required?
Thanks,
Andrew
_______________________________________________
knot-dns-users mailing list
knot-dns-users(a)lists.nic.cz
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users