dns/master: Let serial number configured by dnssec-signzone

dehydrated
Felix Stupp 4 years ago
parent d8f1b36ee1
commit 0662df1ca5
Signed by: zocker
GPG Key ID: 93E1BD26F6B02FB7

@ -18,7 +18,6 @@ dnssec_key_length: "4096"
main_nameserver_domain: "ns1.{{ domain }}."
responsible_mail_name: "admin.{{ domain }}."
serial_number: "{{ lookup('pipe', 'date +\"%Y%m%d%H\"') }}"
refresh: 86400
retry: 7200
expire: 3600000

@ -1,6 +1,6 @@
$TTL 86400
@ IN SOA {{ main_nameserver_domain }} {{ responsible_mail_name }} (
{{ serial_number }}
0
{{ refresh }}
{{ retry }}
{{ expire }}

@ -16,7 +16,7 @@ ${signed_file}: ${db_file}
dnssec-signzone \
-3 $$(head -c 1000 /dev/urandom | sha1sum | cut -b 1-16) \
-a \
-N KEEP \
-N unixtime \
-o {{ domain | quote }} \
-f "$@" \
"$<"

Loading…
Cancel
Save