isc/keyzone.py should invoke named-compilezone to also consider journal files
Description / Request / Links / references
named-compilezone is invoked in the following way:
fp, _ = Popen([czpath, "-o", "-", name, filename],
This does not take into account any journals, so with dynamic updates and/or inline signing, the data read in, might actually not be the real deal. To make sure to load/analyze the correct data
named-compilezone should be invoked with the
-j flag, which, according to the man page does the following:
-j When loading a zone file, read the journal if it exists. The journal file name is assumed to be the zone file name appended with the string .jnl.
If the file does not exist, this option is simply ignored, so simply adding it uncoditionally should not do any harm as far as I can tell.