wytze@deboca.net
660fb8dff6
Update CAA record to contain a valid mailto: URL.
...
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2705 14b1bab8-4ef6-0310-b690-991c95c89dfd
2018-05-02 13:15:58 +00:00
wytze@deboca.net
396ec2467c
Zone updates up to 25 February 2018.
...
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2695 14b1bab8-4ef6-0310-b690-991c95c89dfd
2018-02-25 09:45:00 +00:00
wytze@deboca.net
c2227d5a9d
Upgrade to new release: 4.1.12.
...
Set TTL for SOA to 1 hour, and SOA expire time to 7 days, per web recommendations.
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2685 14b1bab8-4ef6-0310-b690-991c95c89dfd
2017-05-28 09:06:26 +00:00
wytze@deboca.net
ccbc0a84ca
Upgrade OpenDNSSEC software to version 2.0.0-1.
...
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2658 14b1bab8-4ef6-0310-b690-991c95c89dfd
2016-07-16 15:35:41 +00:00
wytze@deboca.net
5dafcb4700
ODS-NOTES: Update instructions for key rollover.
...
keylist: Status on 20151026 after KSK key rollover, submitting new DS hashes and issuing
ods-ksmutil key ds-seen for the ready KSK's. The new KSK goes from ready to active,
the old KSK from active to retire. Note that cacert.community still needs to be done.
cacert.*: Disable IPv6 address for ns3, because this host is currently lacking IPv6 connectivity.
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2619 14b1bab8-4ef6-0310-b690-991c95c89dfd
2015-10-31 14:55:19 +00:00
wytze@deboca.net
3a45494988
Update IPv4 and IPv6 addresses for ns4.cacert.org aka ns-ext.nlnetlabs.nl.
...
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2582 14b1bab8-4ef6-0310-b690-991c95c89dfd
2014-09-19 09:02:26 +00:00
wytze@deboca.net
8d476903f2
Add new (signed) zone cacert.community.
...
Add zone file for reverse IPv4 for CAcert 213.154.225.224/27.
Add IPv6 address for ns1.cacert.com and ns1.cacert.net.
Drop obsolete dlv record.
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2561 14b1bab8-4ef6-0310-b690-991c95c89dfd
2014-06-11 10:54:59 +00:00
wytze@deboca.net
d35d204bed
Update A and AAAA records for ns3 after server migration of mars.overmeer.net.
...
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2502 14b1bab8-4ef6-0310-b690-991c95c89dfd
2013-06-01 09:16:25 +00:00
wytze@deboca.net
9da4b0b01b
Drop nameserver ns2 because it will be taken out of service soon.
...
A corresponding change has already been made in the GKG.NET registry.
Drop newsys.gun.de secondary nameserver for cacert.{org,net,com} because it
will be taken out of service soon, and drop its TSIG key as well.
Add temporary experimental A and AAAA records for wwwdb and securedb,
as part of the migration of CAcert's main webserver to new hardware.
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2482 14b1bab8-4ef6-0310-b690-991c95c89dfd
2013-03-17 10:24:21 +00:00
wytze@deboca.net
aeb3bc5df4
Reduce SOA expiration timer from 1 week to 2 days, in order to comply with a
...
recommendation made in RFC 4641bis: the SOA expiration timer should be between
1/4th and 1/3rd of the size of the signature validity period (1 week at CAcert).
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2370 14b1bab8-4ef6-0310-b690-991c95c89dfd
2012-04-17 07:10:49 +00:00
wytze@deboca.net
3f4424d7b6
Add software configuration for CAcert ns server.
...
The primary revision control is kept in RCS on the actual server,
but the RCS logs of that server are also kept in this svn repository.
git-svn-id: http://svn.cacert.org/CAcert/SystemAdministration/ns/var/opendnssec/unsigned@2323 14b1bab8-4ef6-0310-b690-991c95c89dfd
2011-11-22 16:03:52 +00:00