[Pdns-users] PowerDNS 4.1.0 - Unable to enable DNSSEC for Domains

Fabian A. Santiago fsantiago at garbage-juice.com
Wed Dec 6 23:35:42 UTC 2017


On December 6, 2017 6:14:19 PM EST, Moritz Wirth <mw at flanga.io> wrote:
>Hello everybody,
>
> 
>
>I installed PowerDNS 4.10 on CentOS with a MySQL Backend with the how
>to in the docs.
>
> 
>
>I created a new zone using the pdnsutil command and tried to enable
>dnssec for it, however I receive an error message that DNSSEC is not
>supported. 
>
> 
>
>root at ns1]: pdnsutil secure-zone flangadev.network.
>
>Securing zone with default key size
>
>Adding CSK (257) with algorithm ECDSAP256SHA256
>
>No backend was able to secure 'flangadev.network', most likely because
>no DNSSEC
>
>capable backends are loaded, or because the backends have DNSSEC
>disabled.
>
>For the Generic SQL backends, set the 'gsqlite3-dnssec',
>'gmysql-dnssec' or
>
>'gpgsql-dnssec' flag. Also make sure the schema has been updated for
>DNSSEC!
>
> 
>
>[root at ns1]: pdnsutil show-zone flangadev.network.
>
>This is a Native zone
>
>Zone is not actively secured
>
>Metadata items: None
>
>No keys for zone 'flangadev.network'.
>
> 
>
>Could somebody give me a hint? It is a standard CentOS 7 Installation
>with the PDNS and the pdns-backend-gmysql package, Changes to the
>configuration are only done for the API and the DB Connection.
>
> 
>
>Best regards,
>
> 
>
>Moritz 

Did you add:

gmysql-dnssec

To your pdns.conf section along with your storage backend settings? 
--

Thanks,

Fabian S.

OpenPGP: 3C3FA072ACCB7AC5DB0F723455502B0EEB9070FC


More information about the Pdns-users mailing list