Menu

#5552 Fatal error signing DNS zone

1.990
closed-fixed
nobody
9
2022-03-11
2022-03-09
Lomedhi
No

When Webmin attempts to re-sign a zone after records are modified, it produces this error and the operation fails:

dnssec-signzone: fatal: Zone contains NSEC records. Use -u to update to NSEC3.

This has been confirmed by others on the Virtualmin forums. We have worked around the issue by downgrading to Webmin 1.984.

Discussion

  • Lomedhi

    Lomedhi - 2022-03-11

    I'm using ECDSAP384SHA384. Not sure if the others who have encountered the issue are using the same.

     
  • Jamie Cameron

    Jamie Cameron - 2022-03-11

    Ah .. so in that patch, we changed from NSEC to NSEC3 when using ECDSAP384SHA384 (among others). It seems like the correct fix is to use the -u flag to update the record type..

    If you can, try applying this patch and see if it helps : https://github.com/webmin/webmin/commit/cef983f4f20e6375de745cfa39dece4dcc166b63

     
  • Lomedhi

    Lomedhi - 2022-03-11

    Yes, that worked for me.

     
  • Jamie Cameron

    Jamie Cameron - 2022-03-11
    • status: open --> closed-fixed
     
  • Jamie Cameron

    Jamie Cameron - 2022-03-11

    Excellent! This will be in the next Webmin release ..

     

Log in to post a comment.

MongoDB Logo MongoDB