summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAge
* do not hardcode paths to dnssec tools, moved to /usr/bin, againHEADmasterAntoine Beaupré4 days
* fix deprecation warningAntoine Beaupré4 days
* do not hardcode paths to dnssec tools, moved to /usr/binAntoine Beaupré4 days
* fix warning about tempfile command deprecationAntoine Beaupré2022-05-16
* Merge remote-tracking branch 'dsa/master'Antoine Beaupré2022-05-16
|\
| * When moving keys to the attic, give them a timestamp extension.Peter Palfrader2022-05-05
| * now that postpub is 0, let's keep the revoked one around for another 15 days,...Peter Palfrader2021-06-17
| * set postpub time to 0, so we do not keep a revoked KSK in zone that is not si...Peter Palfrader2021-06-17
| * manage-dnssec-keys: run with python3Julien Cristau2020-12-21
| * manage-dnssec-keys: replace "map" and "filter" calls with list comprehensionsJulien Cristau2020-12-21
| * manage-dnssec-keys: use io.open and explicit encodingJulien Cristau2020-12-21
| * manage-dnssec-keys: decode output from dnssec-settimeJulien Cristau2020-12-17
| * manage-dnssec-keys: fix flake8 warning about ambiguous variable nameJulien Cristau2020-12-17
| * manage-dnssec-keys: use print_functionJulien Cristau2020-12-17
* | now that postpub is 0, let's keep the revoked one around for another 15 days,...Peter Palfrader2021-06-17
* | set postpub time to 0, so we do not keep a revoked KSK in zone that is not si...Peter Palfrader2021-06-17
|/
* Add nagios check (wrapper) scriptsPeter Palfrader2019-10-08
* Add getconf to a common.shPeter Palfrader2019-10-08
* buster settime has slightly different output -- update parserPeter Palfrader2019-10-08
* update-keys: check if auto-dns/zones! is presentPeter Palfrader2019-10-08
* update-keys: check if auto-dns is presentPeter Palfrader2019-10-08
* update: do not fail if auto-dns is not present, 2Peter Palfrader2019-10-08
* update: do not fail if auto-dns is not preset. do not run update-geo if not ...Peter Palfrader2019-10-08
* Add our dnssec-coverage forkPeter Palfrader2019-10-08
* Create keys for zones from /etc/bind/named.conf.puppet-miscPeter Palfrader2019-07-07
* dns.zone cares about TTLs in busterPeter Palfrader2019-05-06
* However, we need to set postpub explicitlyPeter Palfrader2018-11-14
* Revert "also keep keys for single-keytype zones around for a bit"Peter Palfrader2018-11-14
* also keep keys for single-keytype zones around for a bitPeter Palfrader2018-11-14
* fix key removal/archive timing logicPeter Palfrader2018-11-14
* delete KSKs only 30 days after we stop using themPeter Palfrader2018-10-24
* dnssec-settime now supports "all" for metadata flagsPeter Palfrader2018-10-24
* delete old keys in normal operationsPeter Palfrader2018-10-24
* move old and obsolete keys out of the active keydirPeter Palfrader2018-10-24
* manage-dnssec-keys: support moving obsolete keys to an atticPeter Palfrader2018-10-24
* define keyattic dirPeter Palfrader2018-10-24
* update-mini-nag: actually set BASE tooPeter Palfrader2018-10-24
* Add update-mini-nag script to repoPeter Palfrader2018-10-24
* Add update-geo script to repoPeter Palfrader2018-10-24
* Add update script to repoPeter Palfrader2018-10-24
* set -u in update-keysPeter Palfrader2018-10-24
* Add update-keys to repoPeter Palfrader2018-10-24
* Add basedir to dns-helpers.yaml.samplePeter Palfrader2018-10-24
* manage-dnssec-keys: warn on resolution failure (e.g. SERVFAIL) instead of cra...Julien Cristau2017-12-04
* get-new-key: fix column indizes for dsset filePeter Palfrader2017-07-20
* the SEP constant moved from dns.rdtypes.ANY.DNSKEY to dns.rdtypes.dnskeybase ...Peter Palfrader2017-07-17
* Do not load Python code from YAML filesPaul Wise2017-05-15
* Add get-new-keyPeter Palfrader2016-12-16
* raise life time for KSKs to 2 yearsPeter Palfrader2016-08-07
* Use the correct keytag in warningsPeter Palfrader2016-04-13