Menu

#5613 Warning : The following zones have expired DNSSEC signatures

2.013
open
nobody
None
5
2023-03-03
2023-03-02
No

Suddenly: Use the BIND DNS Server module to either disable DNSSEC for these domains, or check why signing is failing.

Discussion

  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    I will share complete screenshot privately.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    Error!
    Warning : The following zones have expired DNSSEC signatures :
    Use the BIND DNS Server module to either disable DNSSEC for these domains, or check why signing is failing.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    System Information:
    System hostname *m (***** Operating system Rocky Linux 8.7
    Webmin version 2.013 Usermin version 1.861
    Virtualmin version 7.5 Authentic theme version 20.13
    Time on system Wednesday, March 1, 2023 10:26 PM Kernel and CPU Linux 4.18.0-425.13.1.el8_7.x86_64 on x86_64
    Processor information Intel(R) Xeon(R) Gold 6230R CPU @ 2.10GHz, 4 cores System uptime 44 minutes
    Running processes 343 CPU load averages 0.16 (1 min) 0.23 (5 mins) 0.24 (15 mins)
    Real memory 2.55 GiB used / 927.54 MiB cached / 7.55 GiB total Virtual memory 0 bytes used / 1.99 GiB total
    Local disk space 5.64 GiB used / 152.31 GiB free / 157.95 GiB total Package updates All installed packages are up to date
    Error!
    Warning : The following zones have expired DNSSEC signatures :

    ****etc
    Use the BIND DNS Server module to either disable DNSSEC for these domains, or check why signing is failing.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    .

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    why can't i delete this?

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    Still same problem.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02
     

    Last edit: Tom MacKenzie 2023-03-02
  • Jamie Cameron

    Jamie Cameron - 2023-03-02

    What happens if you go to Webmin -> Servers -> BIND DNS Server, click on one of the domains, then on the DNSSEC icon?

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    DNSSEC Parameters:
    Name TTL Hash algorithm NSEC3 flags Number of hash iterations Salt string
    domain.com. 3600 1 0 10 -

    If I click on the Setup DNSSEC Key, everything looks normal, meaning there is a key set up for sure.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    I did not have Automatic key re-signing enabled. I have enabled it.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-02

    Do I have to manually re-sign each domain? Or should it update automatically?

     
  • Jamie Cameron

    Jamie Cameron - 2023-03-03

    It should update automatically, as long as DNSSEC is shown as enabled for each domain.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-03

    Yup, thanks again for your assistance. All good now.

     
  • Tom MacKenzie

    Tom MacKenzie - 2023-03-03

    Disregard this post.

     

    Last edit: Tom MacKenzie 2023-03-03

Log in to post a comment.