Follow-up from "kasp: Add test case for migrating KSK/ZSK to CSK"
The following discussion from !7306 (merged) should be addressed:
-
@marka started a discussion: (+4 comments) We also need a test without
-P sync
. Lots of zones being converted to dnssec-policy will never have set-P sync
. The key in the triggering issue only had:; This is a key-signing key, keyid ${ID1}, for my.domain. ; Created: 20200401100731 (Wed Apr 1 13:07:31 2020) ; Publish: 20200401100731 (Wed Apr 1 13:07:31 2020) ; Activate: 20200401100731 (Wed Apr 1 13:07:31 2020) my.domain. IN DNSKEY 257 3 13 <X3>