Forum Discussion

Lokesh's avatar
Lokesh
Icon for Nimbostratus rankNimbostratus
Aug 02, 2019

DNSSEC KSK Key Cannot Auto Rollover

 

1. In first, there is only ID12 key exist which Expiration Time is 2019-07-31.

 

2. I expected that there is a new key generated on 2019-07-11 but it does not show.

 

3. I manual change the expiration Time of ID 12 to 2019-08-30, then a new key ID 13 appear.

 

4. In conclusion, if I do not manual change the Expiration Time of ID 12. There is no any key available after 2019-07-31.

 

Not sure it's related to Bug , I am not able to find bug.

 

  • Hi,

     

    I'm working with DNSSEC on v13.1.1.5 since v11.5 and I honestly found no bugs on this feature.

    Maybe you need to double check key setting for the automatic management rollover you are using, I don't know :/ Could you confirm the BIG-IP version and that's all correct on automatic KSK settings?

     

    Best regards.

      • cjunior's avatar
        cjunior
        Icon for Nacreous rankNacreous

        Yes, there are issues that I have not experienced (lucky :)

        Is this your case?

        https://support.f5.com/csp/article/K51064420

        Regards