Skip to content

How to create TLSA RR with rollover private key? #10

@blackbit42

Description

@blackbit42

To avoid issues with excessively caching DNS resolvers (i.e. resolvers that do not honor TTL), it's common practice to generate a so called rollover private key when a TLS certificate is refreshed, e.g. via ACME.
How can generate (and deploy) a TLSA RR for a rollover key with danebot?
A naive attempt - pointing danebot to the last certificate and the new key - unsurprisingly results in:

Error: key does not belong to certificate: public key mismatch

as it's explicitly checked if the separately supplied private key matches the certificate.

Is support for rollover keys unimplemented? If so, can this be added?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions