Lines Matching refs:keyroll

174 dnssec_policy_add_generate_key_create_at(keyroll_t *keyroll, struct dnssec_policy_key_suite *kr, ti…  in dnssec_policy_add_generate_key_create_at()  argument
205 keyroll->domain, kr->name, epoch, epoch, &n_fw, in dnssec_policy_add_generate_key_create_at()
245 …if(FAIL(ret = keyroll_generate_dnskey_ex(keyroll, kr->key->size, kr->key->algorithm, ONE_SECOND_US… in dnssec_policy_add_generate_key_create_at()
263 …log_debug("dnssec-policy: %{dnsname}: %s: key created set at %U", keyroll->domain, kr->name, alarm… in dnssec_policy_add_generate_key_create_at()
278 dnssec_policy_add_generate_key_active_at(keyroll_t *keyroll, struct dnssec_policy_key_suite *kr, ti… in dnssec_policy_add_generate_key_active_at() argument
344 …{dnsname}: %s: base create: %w <= public: %w <= activate: %w : %U (%w)", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
366 …ate: %w => publish: %w => activate: %w : %U (after forward correction)", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
397 …licy: %{dnsname}: %s: next activate: %w => publish: %w => activate: %w", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
426 …ed for %.3f days, consider increasing this value to at least %.3f days", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
431 …e in the current activated time window produces an already expired key", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
444 keyroll->domain, kr->name, in dnssec_policy_add_generate_key_active_at()
448 …e}: %s: will generate a key at %U (rule new) to be active at %U (%lli)", keyroll->domain, kr->name… in dnssec_policy_add_generate_key_active_at()
505 ret = dnssec_policy_add_generate_key_create_at(keyroll, kr, creation_epoch, &key); in dnssec_policy_add_generate_key_active_at()
2089 dnssec_policy_key_roll_keys_generate_at(keyroll_t *keyroll, struct dnssec_policy_key_suite *kr, ptr… in dnssec_policy_key_roll_keys_generate_at() argument
2091 const u8 *origin = keyroll->domain; in dnssec_policy_key_roll_keys_generate_at()
2184keyroll->ksk_next_deactivation = ONE_SECOND_US * dnskey_get_inactive_epoch(previous_key); in dnssec_policy_key_roll_keys_generate_at()
2188keyroll->zsk_next_deactivation = ONE_SECOND_US * dnskey_get_inactive_epoch(previous_key); in dnssec_policy_key_roll_keys_generate_at()
2193 keyroll->ksk_next_deactivation, keyroll->zsk_next_deactivation); in dnssec_policy_key_roll_keys_generate_at()
2199 …if(FAIL(ret = dnssec_policy_add_generate_key_create_at(keyroll, kr, previous_key->epoch_created, N… in dnssec_policy_key_roll_keys_generate_at()
2206 … if(FAIL(ret = dnssec_policy_add_generate_key_active_at(keyroll, kr, previous_end_period + 60))) in dnssec_policy_key_roll_keys_generate_at()
2248 …if(FAIL(ret = dnssec_policy_add_generate_key_create_at(keyroll, kr, now - delta, NULL))) // works … in dnssec_policy_key_roll_keys_generate_at()
2257 …if(FAIL(ret = dnssec_policy_add_generate_key_active_at(keyroll, kr, now))) // @note : only works o… in dnssec_policy_key_roll_keys_generate_at()
2273 dnssec_policy_process_at(keyroll_t *keyroll, const dnssec_policy *policy, time_t now) in dnssec_policy_process_at() argument
2281 const u8 *origin = keyroll->domain; in dnssec_policy_process_at()
2399 … if(FAIL(ret = dnssec_policy_key_roll_keys_generate_at(keyroll, kr, &key_roll_keys[ksi], now))) in dnssec_policy_process_at()
2417 dnssec_policy_process(keyroll_t *keyroll, const dnssec_policy *policy, s64 from, s64 until) in dnssec_policy_process() argument
2430 …log_info("keyroll: %{dnsname} processing: %s from %llU to %llU", keyroll->domain, policy->name, t,… in dnssec_policy_process()
2431 …formatln("keyroll: %{dnsname} processing: %s from %llU to %llU", keyroll->domain, policy->name, t,… in dnssec_policy_process()
2437 if(ISOK(ret = dnssec_policy_process_at(keyroll, policy, t / ONE_SECOND_US))) in dnssec_policy_process()
2439 t = MIN(keyroll->ksk_next_deactivation, keyroll->zsk_next_deactivation); in dnssec_policy_process()
2441 …me}: processed: %s covers: %llU , %llU", keyroll->domain, policy->name, keyroll->ksk_next_deactiva… in dnssec_policy_process()