-
Matthijs Mekking authored
The kasp system tests are updated with 'check_cds' calls that will verify that the correct CDS and CDNSKEY records are published during a rollover and that they are signed with the correct KSK. This requires a change in 'dnssec.c' to check the kasp key states whether the CDS/CDNSKEY of a key should be published or not. If no kasp state exist, fall back to key timings.
c3e0ac86