<div>No local script. I am using snssec-signzone that cam with the installation:</div>
<div> </div>
<div># dnssec-signzone --help<br>Version: 9.6.2-P1-RedHat-9.6.2-3.P1<br><br></div>
<div class="gmail_quote">On Thu, May 20, 2010 at 12:26 PM, Stephane Bortzmeyer <span dir="ltr"><<a href="mailto:bortzmeyer@nic.fr">bortzmeyer@nic.fr</a>></span> wrote:<br>
<blockquote style="BORDER-LEFT: #ccc 1px solid; MARGIN: 0px 0px 0px 0.8ex; PADDING-LEFT: 1ex" class="gmail_quote">On Thu, May 20, 2010 at 12:10:53PM -0700,<br> itservices88 <<a href="mailto:itservices88@gmail.com">itservices88@gmail.com</a>> wrote<br>
<div class="im"> a message of 92 lines which said:<br><br>> # dnssec-signzone -N INCREMENT <a href="http://mydomain.org/" target="_blank">mydomain.org</a><br>> Verifying the zone using the following algorithms: RSASHA1.<br>
> Missing RSASHA1 signature for . NSEC<br>> The zone is not fully signed for the following algorithms: RSASHA1.<br>> dnssec-signzone: fatal: DNSSEC completeness test failed.<br><br></div>I do not find these error messages in BIND source code. Are you sure<br>
you use the pristine dnssec-signzone and not, say, a local custom<br>script?<br><br>(dnssec-signzone is supposed to sign the zone, not to check that it is<br>signed.)<br></blockquote></div><br>