inactivating and deleting DNSSEC keys

David Newman dnewman at
Wed Oct 9 20:45:28 UTC 2013

On 10/9/13 1:24 PM, Mark Andrews wrote:

>> In UTC terms, we've already passed the key's deletion date. Can I
>> retroactively extend the key's deletion date?
> Yes.  The files are not removed.  You will need to tell named to re-read
> the .private file using "rndc signzone" after setting the time the deletion
> time.

Thanks, Mark. The signzone command didn't work, but "rndc sign <zone>"
worked fine.


More information about the bind-users mailing list