Inline-signing / dnssec-policy: Signed SOA serial diverges from source serial causing monitoring warnings

Jan-Piet Mens list at mens.de
Tue Jul 21 17:43:51 UTC 2026


>Is there a recommended migration strategy to move from YYYYMMDDNN to Unix timestamp serials?

In addition to what Ondrej responded, if the secondaries are under your control, set whichever SOA serial you want to and then, on the secondary, force a retransfer with the likes of `rndc retransfer $zone'.

	-JP


More information about the bind-users mailing list