DNSSEC, purge old unused keys
Currently, old keys are not removed from the zone configuration during rollovers.
Old keys can be purged when new the rollover is finished.
Self sign-up has been disabled due to increased spam activity. If you want to get access, please send an email to a project owner (preferred) or at gitlab(at)nic(dot)cz. We apologize for the inconvenience.
Currently, old keys are not removed from the zone configuration during rollovers.
Old keys can be purged when new the rollover is finished.
Milestone changed to backburner
This seems like a good thing to add – I was going to suggest it myself. I'd propose adding another timer parameter to the KASP-DB for the final deletion of an old key, perhaps with a default setting of some fixed time after the 'remove' parameter.
I was thinking about three possible approaches:
I'm not sure what's best.
Reassigned to @fsiroky
Mentioned in merge request !595 (merged)
Mentioned in merge request !597 (merged)
closed via commit 7fa8ad0b
closed via merge request !597 (merged)
mentioned in commit 7fa8ad0b