12010-02-21 19:43:15.018: debug: 	Check RFC5011 status
22010-02-21 19:43:15.018: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
32010-02-21 19:43:15.018: debug: 	Check KSK status
42010-02-21 19:43:15.018: debug: 	No active KSK found: generate new one
52010-02-21 19:43:15.330: info: "dyn.example.net.": generated new KSK 52935
62010-02-21 19:43:15.330: debug: 	Check ZSK status
72010-02-21 19:43:15.330: debug: 	No active ZSK found: generate new one
82010-02-21 19:43:15.368: info: "dyn.example.net.": generated new ZSK 30323
92010-02-21 19:43:15.368: debug: 	Re-signing necessary: Modfied zone key set
102010-02-21 19:43:15.368: notice: "dyn.example.net.": re-signing triggered: Modfied zone key set
112010-02-21 19:43:15.368: debug: 	Writing key file "./dyn.example.net/dnskey.db"
122010-02-21 19:43:15.368: debug: 	Signing zone "dyn.example.net."
132010-02-21 19:43:15.368: notice: "dyn.example.net.": freeze dynamic zone
142010-02-21 19:43:15.368: debug: 	freeze dynamic zone "dyn.example.net."
152010-02-21 19:43:15.368: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
162010-02-21 19:43:15.374: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
172010-02-21 19:43:15.374: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
182010-02-21 19:43:15.382: debug: 	  Cmd dnssec-signzone return: "dnssec-signzone: fatal: Zone contains NSEC records.  Use -u to update to NSEC3."
192010-02-21 19:43:15.382: error: "dyn.example.net.": signing failed!
202010-02-21 19:43:15.382: notice: "dyn.example.net.": thaw dynamic zone
212010-02-21 19:43:15.382: debug: 	thaw dynamic zone "dyn.example.net."
222010-02-21 19:43:15.382: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
232010-02-21 19:45:36.415: debug: 	Check RFC5011 status
242010-02-21 19:45:36.416: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
252010-02-21 19:45:36.416: debug: 	Check KSK status
262010-02-21 19:45:36.416: debug: 	Check ZSK status
272010-02-21 19:45:36.416: debug: 	Re-signing not necessary!
282010-02-21 19:45:36.416: debug: 	Check if there is a parent file to copy
292010-02-21 19:45:41.448: debug: 	Check RFC5011 status
302010-02-21 19:45:41.448: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
312010-02-21 19:45:41.448: debug: 	Check KSK status
322010-02-21 19:45:41.448: debug: 	Check ZSK status
332010-02-21 19:45:41.448: debug: 	Re-signing necessary: Option -f
342010-02-21 19:45:41.448: notice: "dyn.example.net.": re-signing triggered: Option -f
352010-02-21 19:45:41.448: debug: 	Writing key file "./dyn.example.net/dnskey.db"
362010-02-21 19:45:41.448: debug: 	Signing zone "dyn.example.net."
372010-02-21 19:45:41.448: notice: "dyn.example.net.": freeze dynamic zone
382010-02-21 19:45:41.448: debug: 	freeze dynamic zone "dyn.example.net."
392010-02-21 19:45:41.448: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
402010-02-21 19:45:41.457: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
412010-02-21 19:45:41.458: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
422010-02-21 19:45:41.473: debug: 	  Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 generation requested with NSEC only DNSKEY"
432010-02-21 19:45:41.473: error: "dyn.example.net.": signing failed!
442010-02-21 19:45:41.473: notice: "dyn.example.net.": thaw dynamic zone
452010-02-21 19:45:41.473: debug: 	thaw dynamic zone "dyn.example.net."
462010-02-21 19:45:41.473: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
472010-02-21 19:47:06.899: debug: 	Check RFC5011 status
482010-02-21 19:47:06.899: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
492010-02-21 19:47:06.899: debug: 	Check KSK status
502010-02-21 19:47:06.899: debug: 	Check ZSK status
512010-02-21 19:47:06.899: debug: 	Re-signing necessary: Option -f
522010-02-21 19:47:06.899: notice: "dyn.example.net.": re-signing triggered: Option -f
532010-02-21 19:47:06.899: debug: 	Writing key file "./dyn.example.net/dnskey.db"
542010-02-21 19:47:06.900: debug: 	Signing zone "dyn.example.net."
552010-02-21 19:47:06.900: notice: "dyn.example.net.": freeze dynamic zone
562010-02-21 19:47:06.900: debug: 	freeze dynamic zone "dyn.example.net."
572010-02-21 19:47:06.900: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
582010-02-21 19:47:06.910: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
592010-02-21 19:47:06.910: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
602010-02-21 19:47:06.926: debug: 	  Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 iterations too big for weakest DNSKEY strength. Maximum iterations allowed 0."
612010-02-21 19:47:06.926: error: "dyn.example.net.": signing failed!
622010-02-21 19:47:06.926: notice: "dyn.example.net.": thaw dynamic zone
632010-02-21 19:47:06.926: debug: 	thaw dynamic zone "dyn.example.net."
642010-02-21 19:47:06.926: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
652010-02-21 19:58:40.972: debug: 	Check RFC5011 status
662010-02-21 19:58:40.972: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
672010-02-21 19:58:40.972: debug: 	Check KSK status
682010-02-21 19:58:40.972: debug: 	Check ZSK status
692010-02-21 19:58:40.973: debug: 	Re-signing necessary: Option -f
702010-02-21 19:58:40.973: notice: "dyn.example.net.": re-signing triggered: Option -f
712010-02-21 19:58:40.973: debug: 	Writing key file "./dyn.example.net/dnskey.db"
722010-02-21 19:58:40.973: debug: 	Signing zone "dyn.example.net."
732010-02-21 19:58:40.973: notice: "dyn.example.net.": freeze dynamic zone
742010-02-21 19:58:40.973: debug: 	freeze dynamic zone "dyn.example.net."
752010-02-21 19:58:40.973: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
762010-02-21 19:58:40.982: debug: 	Dynamic Zone signing: zone file manually edited: Use it as new input file
772010-02-21 19:58:40.982: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
782010-02-21 19:58:40.983: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
792010-02-21 19:58:40.999: debug: 	  Cmd dnssec-signzone return: "dnssec-signzone: fatal: NSEC3 iterations too big for weakest DNSKEY strength. Maximum iterations allowed 0."
802010-02-21 19:58:40.999: error: "dyn.example.net.": signing failed!
812010-02-21 19:58:40.999: notice: "dyn.example.net.": thaw dynamic zone
822010-02-21 19:58:40.999: debug: 	thaw dynamic zone "dyn.example.net."
832010-02-21 19:58:40.999: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
842010-02-21 20:00:48.833: debug: 	Check RFC5011 status
852010-02-21 20:00:48.833: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
862010-02-21 20:00:48.833: debug: 	Check KSK status
872010-02-21 20:00:48.833: debug: 	Check ZSK status
882010-02-21 20:00:48.833: debug: 	Re-signing necessary: Option -f
892010-02-21 20:00:48.833: notice: "dyn.example.net.": re-signing triggered: Option -f
902010-02-21 20:00:48.833: debug: 	Writing key file "./dyn.example.net/dnskey.db"
912010-02-21 20:00:48.834: debug: 	Signing zone "dyn.example.net."
922010-02-21 20:00:48.834: notice: "dyn.example.net.": freeze dynamic zone
932010-02-21 20:00:48.834: debug: 	freeze dynamic zone "dyn.example.net."
942010-02-21 20:00:48.834: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
952010-02-21 20:00:48.844: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
962010-02-21 20:00:48.844: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
972010-02-21 20:00:48.878: debug: 	  Cmd dnssec-signzone return: "zone.db.dsigned"
982010-02-21 20:00:48.878: notice: "dyn.example.net.": thaw dynamic zone
992010-02-21 20:00:48.878: debug: 	thaw dynamic zone "dyn.example.net."
1002010-02-21 20:00:48.878: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
1012010-02-21 20:00:48.884: debug: 	Signing completed after 0s.
1022010-02-21 20:01:11.175: debug: 	Check RFC5011 status
1032010-02-21 20:01:11.175: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
1042010-02-21 20:01:11.175: debug: 	Check KSK status
1052010-02-21 20:01:11.175: debug: 	Check ZSK status
1062010-02-21 20:01:11.176: debug: 	Re-signing necessary: Option -f
1072010-02-21 20:01:11.176: notice: "dyn.example.net.": re-signing triggered: Option -f
1082010-02-21 20:01:11.176: debug: 	Writing key file "./dyn.example.net/dnskey.db"
1092010-02-21 20:01:11.176: debug: 	Signing zone "dyn.example.net."
1102010-02-21 20:01:11.176: notice: "dyn.example.net.": freeze dynamic zone
1112010-02-21 20:01:11.176: debug: 	freeze dynamic zone "dyn.example.net."
1122010-02-21 20:01:11.176: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
1132010-02-21 20:01:11.181: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
1142010-02-21 20:01:11.181: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
1152010-02-21 20:01:11.202: debug: 	  Cmd dnssec-signzone return: "zone.db.dsigned"
1162010-02-21 20:01:11.202: notice: "dyn.example.net.": thaw dynamic zone
1172010-02-21 20:01:11.203: debug: 	thaw dynamic zone "dyn.example.net."
1182010-02-21 20:01:11.203: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
1192010-02-21 20:01:11.208: debug: 	Signing completed after 0s.
1202010-02-21 20:01:17.175: debug: 	Check RFC5011 status
1212010-02-21 20:01:17.175: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
1222010-02-21 20:01:17.175: debug: 	Check KSK status
1232010-02-21 20:01:17.175: debug: 	Check ZSK status
1242010-02-21 20:01:17.176: debug: 	Re-signing not necessary!
1252010-02-21 20:01:17.176: debug: 	Check if there is a parent file to copy
1262010-02-25 23:42:29.326: debug: 	Check RFC5011 status
1272010-02-25 23:42:29.326: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
1282010-02-25 23:42:29.326: debug: 	Check KSK status
1292010-02-25 23:42:29.326: debug: 	Check ZSK status
1302010-02-25 23:42:29.326: debug: 	Re-signing necessary: re-signing interval (2d) reached
1312010-02-25 23:42:29.326: notice: "dyn.example.net.": re-signing triggered: re-signing interval (2d) reached
1322010-02-25 23:42:29.326: debug: 	Writing key file "./dyn.example.net/dnskey.db"
1332010-02-25 23:42:29.327: debug: 	Signing zone "dyn.example.net."
1342010-02-25 23:42:29.327: notice: "dyn.example.net.": freeze dynamic zone
1352010-02-25 23:42:29.327: debug: 	freeze dynamic zone "dyn.example.net."
1362010-02-25 23:42:29.327: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
1372010-02-25 23:42:29.388: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
1382010-02-25 23:42:29.425: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
1392010-02-25 23:42:29.471: debug: 	  Cmd dnssec-signzone return: "zone.db.dsigned"
1402010-02-25 23:42:29.471: notice: "dyn.example.net.": thaw dynamic zone
1412010-02-25 23:42:29.471: debug: 	thaw dynamic zone "dyn.example.net."
1422010-02-25 23:42:29.471: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
1432010-02-25 23:42:29.486: debug: 	Signing completed after 0s.
1442010-03-02 10:59:46.770: debug: 	Check RFC5011 status
1452010-03-02 10:59:46.770: debug: 		->not a rfc5011 zone, looking for a regular ksk rollover
1462010-03-02 10:59:46.770: debug: 	Check KSK status
1472010-03-02 10:59:46.770: debug: 	Check ZSK status
1482010-03-02 10:59:46.770: debug: 	Re-signing necessary: re-signing interval (2d) reached
1492010-03-02 10:59:46.770: notice: "dyn.example.net.": re-signing triggered: re-signing interval (2d) reached
1502010-03-02 10:59:46.770: debug: 	Writing key file "./dyn.example.net/dnskey.db"
1512010-03-02 10:59:46.770: debug: 	Signing zone "dyn.example.net."
1522010-03-02 10:59:46.770: notice: "dyn.example.net.": freeze dynamic zone
1532010-03-02 10:59:46.770: debug: 	freeze dynamic zone "dyn.example.net."
1542010-03-02 10:59:46.770: debug: 	  Run cmd "/usr/local/sbin/rndc freeze dyn.example.net."
1552010-03-02 10:59:46.852: debug: 	Dynamic Zone signing: copy old signed zone file ./dyn.example.net/zone.db.dsigned to new input file ./dyn.example.net/zone.db
1562010-03-02 10:59:46.875: debug: 	  Run cmd "cd ./dyn.example.net; /usr/local/sbin/dnssec-signzone -n 1 -u -3 76931F -C -g -p -d ../keysets -o dyn.example.net. -e +518400  -N increment -f zone.db.dsigned zone.db K*.private 2>&1"
1572010-03-02 10:59:46.950: debug: 	  Cmd dnssec-signzone return: "zone.db.dsigned"
1582010-03-02 10:59:46.950: notice: "dyn.example.net.": thaw dynamic zone
1592010-03-02 10:59:46.950: debug: 	thaw dynamic zone "dyn.example.net."
1602010-03-02 10:59:46.950: debug: 	  Run cmd "/usr/local/sbin/rndc thaw dyn.example.net."
1612010-03-02 10:59:46.964: debug: 	Signing completed after 0s.
162