search for: zsk

Displaying 11 results from an estimated 11 matches for "zsk".

Did you mean: ask
2010 Jan 12
0
Why agent log out automaticly?
...ault', on SIP/ivan-00000013 -- Stopped music on hold on SIP/3172841667-00000012 -- agent_call, call to agent '1002' call on 'SIP/3172841667-00000012' -- <SIP/3172841667-00000012> Playing 'beep' (language 'en') -- Stopped music on hold on SIP/zsk-00000006 -- agent_call, call to agent '1001' call on 'SIP/zsk-00000006' -- <SIP/zsk-00000006> Playing 'beep' (language 'en') -- Agent/1002 answered SIP/ivan-00000013 -- Started music on hold, class 'default', on SIP/zsk-00000006 -- S...
2017 Feb 01
4
Script not running correctly as cronjob
...:28 DNSSEC-Signierung abgeschlossen The script deletes the old signed zones, but don't resign it. The mail is also sent. Below the script. Anybody an idea why it doesn't work in cron?^ I cannot find any error in any log. Best regards Daniel #!/bin/bash KSKDIR="/etc/named/KSK" ZSKDIR="/etc/named/ZSK" ZONEDIR="/var/named/chroot/var/named" LOG="/var/named/chroot/var/log/dnssec_resign.log" MAILREC="monitor at xx" #delete old signed files rm -rf $ZONEDIR/*.signed #delete the old log rm -rf $LOG #read the zonefiles ZONEFILES=$(ls -p $ZON...
2016 Apr 27
0
DNSSEC / Security stats (forked from php thread)
...E, DNSSEC greatly improves security for the 7% (and growing) recursive resolvers that enforce DNSSEC. Before deploying DNSSEC do a lot of reading on it, because if you screw it up, those 7% enforcing recursive resolvers won't resolve your zone. I personally use a 2048-bit KSK and a 1024-bit ZSK. The KSK is what you have to get the DS record for uploaded to your TLS, and it should be rotated once a year. The ZSK is just in your zone, best practice says to rotate once a month but I rotate once a week, every Sunday. It should be automated, so it doesn't hurt to do it more often than...
2015 Dec 24
2
Centos7 poblems with dnssec-keygen
I am reading: https://www.centos.org/docs/5/html/Deployment_Guide-en-US/s1-bind-rndc.html I have bind installed and default config running. I have not applied my customizations yet. The first step I am taking is getting rndc.key created. So reading the guide I am trying to run (while logged in as root, and in /etc): dnssec-keygen -a hmac-md5 -b 256 -n HOST rndc.key The system is just
2017 Feb 01
1
Script not running correctly as cronjob
...nd examine the output that gets mailed to you. The -x tells it to echo each command it is about to execute. That will help you to see how far it is getting. Further comments below. Cheers Tony > Best regards > Daniel > > > #!/bin/bash > KSKDIR="/etc/named/KSK" > ZSKDIR="/etc/named/ZSK" > ZONEDIR="/var/named/chroot/var/named" > LOG="/var/named/chroot/var/log/dnssec_resign.log" > MAILREC="monitor at xx" > > #delete old signed files > rm -rf $ZONEDIR/*.signed > > #delete the old log > rm -rf $LO...
2015 Dec 24
0
Centos7 poblems with dnssec-keygen
...e any processing being done by dnssec-keygen. > > Has anyone else done this? Am I doing things in the right order? If it > works for others, then there is something wrong with my setup... It's working fine for me. I'm using the command ldns-keygen to generate keys though - e.g. ZSK=`/usr/bin/ldns-keygen -a RSASHA1-NSEC3-SHA1 -b 1024 ${zone}` and KSK=`/usr/bin/ldns-keygen -k -a RSASHA1-NSEC3-SHA1 -b 2048 ${zone}` ldns-keygen is from the ldns package. Mine is currently all scripted and automated, has been for months - I started with an Ubuntu tutorial though, not CentOS do...
2017 Feb 01
0
Script not running correctly as cronjob
...nd examine the output that gets mailed to you. The -x tells it to echo each command it is about to execute. That will help you to see how far it is getting. Further comments below. Cheers Tony > Best regards > Daniel > > > #!/bin/bash > KSKDIR="/etc/named/KSK" > ZSKDIR="/etc/named/ZSK" > ZONEDIR="/var/named/chroot/var/named" > LOG="/var/named/chroot/var/log/dnssec_resign.log" > MAILREC="monitor at xx" > > #delete old signed files > rm -rf $ZONEDIR/*.signed > > #delete the old log > rm -rf $LO...
2015 Dec 24
2
Centos7 poblems with dnssec-keygen
...eygen. >> >> Has anyone else done this? Am I doing things in the right order? If it >> works for others, then there is something wrong with my setup... > > It's working fine for me. > > I'm using the command ldns-keygen to generate keys though - e.g. > > ZSK=`/usr/bin/ldns-keygen -a RSASHA1-NSEC3-SHA1 -b 1024 ${zone}` > > and > > KSK=`/usr/bin/ldns-keygen -k -a RSASHA1-NSEC3-SHA1 -b 2048 ${zone}` > > ldns-keygen is from the ldns package. > > Mine is currently all scripted and automated, has been for months - I > started with...
2017 Feb 14
8
CentOS 7, systemd, NetworkMangler, oh, my
On 02/13/2017 11:36 AM, peter.winterflood wrote: > On 13/02/17 16:49, James Hogarth wrote: >> On 13 February 2017 at 16:17, peter.winterflood >> <peter.winterflood at ossi.co.uk> wrote: >>> >>> >>> there's a really good solution to this. >>> >>> yum remove NetworkManager* >>> >>> chkconfig network on
2002 Mar 24
1
1024-bit RSA keys in danger of compromise
...qvr2bl7Hth+8UZd7G+L1QR0+bWmphvYpgnJDaZKbB3t 9dsjjMBji8N7lYcgt5ond4uXm+3BXHI83ewhs3rrCNdl7tg1Pb9yrBq9u5+3tRs/ ey7UtokARgQQEQIABgUCOY4pWQAKCRCI5rIBP1q1aY6mAKCJMIcPrmwrwbtiuNw6 KweTr/h3KACg6s9+cyWJoNiBRMGmUXsi+QwQdTuJARwEEAECAAYFAjujhowACgkQ xQIbDGZZweFB4wgAoFPxTdpqpnoeguRMvoUW8TyT2DFw7dc77ubl4R4FWv3P+zSK fkHPv/DgyPJuL6IRxt2zcdPMYBkGw59bTNRSUAShhDXujMjzzN/2vMJv7r8ACTFU 2ER0gNiH1n/dYz2LL1olnM4e7qNbbTJ/VIj2JREmVjwW4M+uOVDFO0N/z8Tkaw5y NhJIiaV65capYNIObnPGrsjffeNF3D471clKG2acQQFH+jV9O891Q/gL2AuIf4lh /SuuFmf0f1uEf+6X6vws5e8ScllIVmF4GhJEO6Pg5Tw5Fu2fp3Ffq8Ms5yBdX2pV O3gWhwAh2mJk5ZtuzC7IOmAvgLvBMUPi56B5wYk...
2009 Jul 23
1
[PATCH server] changes required for fedora rawhide inclusion.
...aT07yp-bN8q32$HBF*|jHkM67pM<xvcD$YA!-s!#ye6mYRuzm-uRYpeJv3;Igko7 zw`FHpbYE at OsEcKl@|f%nk5ycL7BHjG#b_PQ*u|wQ?%PIIBi}nxs^j&e>93xDP3=HB zrNUR~tqVlVuRU^6Njgsc;>Z#VWhXEcnJ3$(VwZ39!;o8CP?UPh<jsMYP|0OP>otUV zl(FW*6_B4I8>uEG;j3P5vJP5wmp?2mlMvFCwr2E`+icu)#_NJCoolluDWKDALtGYS zMCxmO{e1zSkfXdS%S+bDuyq#6vb8oYuQg8o|8qC|VWEQ;(KGzvI|M~0<O#NgU0tL6 zZmBhv7;;Ug?4kvj63-NF(kKraPLhbd&qRXK(-e{kXV}t<R at W*~^o at 41h0W7wZj+b| ziR)0a`2NJcTAMu^a<SC&enm|>8DVQC!#Rx(yi>L$C4D7MOG>wkud^7NfbjdS at 7%FV zV}<jpqu(t(Nt=CcTo(L?iuy+AzBped&1^TC+2%L<5#w{mSK^LuiJ2|A!m$FD%{LS2...