Skip to content

[9.20] new: usr: Support restricted key tag range when generating new keys

It is useful when multiple signers are being used to sign a zone to able to specify a restricted range of range of key tags that will be used by an operator to sign the zone. This adds controls to named (dnssec-policy), dnssec-signzone, dnssec-keyfromlabel and dnssec-ksr (dnssec-policy) to specify such ranges.

Closes #4830 (closed)

Backport of MR !9258 (merged)

Merge request reports