OpenDNSSEC 1.0.0b8

The 8th beta-version of OpenDNSSEC has been released.

The following things are new for this release:

  • ods-ksmutil: KSK rollover now holds at the point where the new key is made active until the command “ds-seen” is issued.
  • ods-ksmutil: “database backup” implemented to safely make a copy of the SQLite enforcer database.


  • Auditor: Crashed on unknown RR class.
  • Signer Engine: NSEC3 RR included wrong information in bitmap (fixed in ldns trunk).
  • Signer Engine: Force a new signed zone if input is reread. Necessary because we cannot recognize if glue or unsigned delegations have been added and/or removed (yet).
  • Signer Engine: Fix adding duplicate signatures in case of single key is being used as both ZSK and KSK.
  • Bugreport #46: Vanishing records
  • KASP Enforcer: Could not handle zones with names longer than 30 characters.

Download the tarball from: opendnssec-1.0.0b8.tar.gz

Comments are closed.