Discussion:
[Opendnssec-user] segfault error 6 in libc-2.23.so
Bas van den Dikkenberg
2017-01-07 11:21:31 UTC
Permalink
Hello,


From today opendnsec enforcerd won't start all i get is :
[ 267.837057] ods-enforcerd[2414]: segfault at 7fa32a56dff8 ip 00007fa32ef1429c sp 00007fa32a56dff0 error 6 in libc-2.23.so[7fa32ee93000+1bf000]

Any one an idee
Bas van den Dikkenberg
2017-01-07 12:37:46 UTC
Permalink
I enabeld some extra debug but stil not clear:

Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] create socket /run/opendnssec/enforcer.sock
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /run/opendnssec with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /run/opendnssec/enforcer.sock with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /var/lib/opendnssec/enforcer with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] drop privileges
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] running as pid 9430
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[1]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[2]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[3]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[4]
Jan 7 13:34:27 Scripting ods-enforcerd: [util] writing pid 9430 to pidfile /run/opendnssec/enforcerd.pid
Jan 7 13:34:27 Scripting ods-enforcerd: [file] open file file=/run/opendnssec/enforcerd.pid mode=writing
Jan 7 13:34:27 Scripting ods-enforcerd: [file] openfile /run/opendnssec/enforcerd.pid count 1
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] enforcer started
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] start command handler
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] start workers
Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] start
Jan 7 13:34:27 Scripting ods-enforcerd: [autostart_cmd] autostart
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [enforce] for next zone
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] taking a break
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]]: perform task [enforce] for next zone
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT zone.id, zone.rev, zone.policyId, zone.name, zone.signconfNeedsWriting, zone.signconfPath, zone.nextChange, zone.ttlEndDs, zone.ttlEndDk, zone.ttlEndRs, zone.rollKskNow, zone.rollZskNow, zone.rollCskNow, zone.inputAdapterType, zone.inputAdapterUri, zone.outputAdapterType, zone.outputAdapterUri, zone.nextKskRoll, zone.nextZskRoll, zone.nextCskRoll FROM zone
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: perform task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies [duration: 0]
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all] generating keys
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] no alarm set
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: perform task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[4]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.denialType = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] update zone: test.local
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updatePolicy: policyName: LAB
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [policy_resalt_task] policies have been updated
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] finished working
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] SIGALRM set
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 6 times: [ SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?]
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 2 times: [ SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?]
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing test.local with policyName LAB
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key a91529a6115e99a514197aca707e39b9 4
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 549bf53b44b04b19a22d7b208f1885c3 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 6738b5dcea086c30106fdf89c7502a10 4
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DS in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 RRSIGDNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key c6d70fba0fb270e07dd24e9bf9fa7731 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 4ad5c47d20fb2a256bc427dccae2f580 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 4ad5c47d20fb2a256bc427dccae2f580 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies done
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] finished working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty
Jan 7 13:34:27 Scripting kernel: [ 4931.783357] ods-enforcerd[9433]: segfault at 7f2b6c2c2ff8 ip 00007f2b7046829c sp 00007f2b6c2c2ff0 error 6 in libc-2.23.so[7f2b703e7000+1bf000]

Van: Bas van den Dikkenberg
Verzonden: zaterdag 7 januari 2017 12:21
Aan: opendnssec-***@lists.opendnssec.org
Onderwerp: segfault error 6 in libc-2.23.so

Hello,


From today opendnsec enforcerd won't start all i get is :
[ 267.837057] ods-enforcerd[2414]: segfault at 7fa32a56dff8 ip 00007fa32ef1429c sp 00007fa32a56dff0 error 6 in libc-2.23.so[7fa32ee93000+1bf000]

Any one an idee
(Berry) A.W. van Halderen
2017-01-08 13:30:28 UTC
Permalink
Which version are you running? I guess an 2.x version..
You can can some more information using a debugger for us:
Run the enforcerd using a debugger like this:
gdb ods-enforcerd
The debugger starts, and reports with a prompt "(gdb)" where you can run
the enforcer in the foreground:
run -d
It will then probably crash and you can get more information using either
bt
Or more extensive with
thread apply all bt

Crashes in libc are mostly memory-allocation problems related, so we
like to hear those.

\Berry
Post by Bas van den Dikkenberg
Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] create socket /run/opendnssec/enforcer.sock
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /run/opendnssec with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /run/opendnssec/enforcer.sock with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [file] create and chown /var/lib/opendnssec/enforcer with user=4294967295 group=4294967295
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] drop privileges
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] running as pid 9430
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[1]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[2]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[3]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[4]
Jan 7 13:34:27 Scripting ods-enforcerd: [util] writing pid 9430 to pidfile /run/opendnssec/enforcerd.pid
Jan 7 13:34:27 Scripting ods-enforcerd: [file] open file file=/run/opendnssec/enforcerd.pid mode=writing
Jan 7 13:34:27 Scripting ods-enforcerd: [file] openfile /run/opendnssec/enforcerd.pid count 1
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] enforcer started
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] start command handler
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] start workers
Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] start
Jan 7 13:34:27 Scripting ods-enforcerd: [autostart_cmd] autostart
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [enforce] for next zone
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [engine] taking a break
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[1]]: perform task [enforce] for next zone
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT zone.id, zone.rev, zone.policyId, zone.name, zone.signconfNeedsWriting, zone.signconfPath, zone.nextChange, zone.ttlEndDs, zone.ttlEndDk, zone.ttlEndRs, zone.rollKskNow, zone.rollZskNow, zone.rollCskNow, zone.inputAdapterType, zone.inputAdapterUri, zone.outputAdapterType, zone.outputAdapterUri, zone.nextKskRoll, zone.nextZskRoll, zone.nextCskRoll FROM zone
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: perform task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies [duration: 0]
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all] generating keys
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] no alarm set
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] start working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: perform task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[4]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.denialType = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] update zone: test.local
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updatePolicy: policyName: LAB
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [policy_resalt_task] policies have been updated
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] finished working
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt] for policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] SIGALRM set
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 6 times: [ SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?]
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 2 times: [ SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?]
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing test.local with policyName LAB
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key a91529a6115e99a514197aca707e39b9 4
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 549bf53b44b04b19a22d7b208f1885c3 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 6738b5dcea086c30106fdf89c7502a10 4
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DS in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 RRSIGDNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key c6d70fba0fb270e07dd24e9bf9fa7731 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: processing key 4ad5c47d20fb2a256bc427dccae2f580 1
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 4ad5c47d20fb2a256bc427dccae2f580 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy says we can (1/3)
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role KSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate] repository SoftHSM role ZSK
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies done
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] finished working
Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty
Jan 7 13:34:27 Scripting kernel: [ 4931.783357] ods-enforcerd[9433]: segfault at 7f2b6c2c2ff8 ip 00007f2b7046829c sp 00007f2b6c2c2ff0 error 6 in libc-2.23.so[7f2b703e7000+1bf000]
Van: Bas van den Dikkenberg
Verzonden: zaterdag 7 januari 2017 12:21
Onderwerp: segfault error 6 in libc-2.23.so
Hello,
[ 267.837057] ods-enforcerd[2414]: segfault at 7fa32a56dff8 ip 00007fa32ef1429c sp 00007fa32a56dff0 error 6 in libc-2.23.so[7fa32ee93000+1bf000]
Any one an idee
_______________________________________________
Opendnssec-user mailing list
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
Bas van den Dikkenberg
2017-01-08 18:24:43 UTC
Permalink
Oke i made output you requested,

But the output file is big 2mb so you download it here: https://www.hobby.nl/images/putty.log

Bas


-----Oorspronkelijk bericht-----
Van: (Berry) A.W. van Halderen [mailto:***@nlnetlabs.nl]
Verzonden: zondag 8 januari 2017 14:30
Aan: Bas van den Dikkenberg <***@Dikkenberg.net>
CC: opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so

Which version are you running? I guess an 2.x version..
You can can some more information using a debugger for us:
Run the enforcerd using a debugger like this:
gdb ods-enforcerd
The debugger starts, and reports with a prompt "(gdb)" where you can run the enforcer in the foreground:
run -d
It will then probably crash and you can get more information using either
bt
Or more extensive with
thread apply all bt

Crashes in libc are mostly memory-allocation problems related, so we like to hear those.

\Berry
Post by Bas van den Dikkenberg
Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] create socket
[file] create and chown /run/opendnssec with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [file]
create and chown /run/opendnssec/enforcer.sock with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [file]
create and chown /var/lib/opendnssec/enforcer with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [engine]
drop privileges Jan 7 13:34:27 Scripting ods-enforcerd: [engine]
running as pid 9430 Jan 7 13:34:27 Scripting ods-enforcerd: create
worker[1] Jan 7 13:34:27 Scripting ods-enforcerd: create worker[2]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[3] Jan 7
13:34:27 Scripting ods-enforcerd: create worker[4] Jan 7 13:34:27
Scripting ods-enforcerd: [util] writing pid 9430 to pidfile
[file] open file file=/run/opendnssec/enforcerd.pid mode=writing Jan
7 13:34:27 Scripting ods-enforcerd: [file] openfile
/run/opendnssec/enforcerd.pid count 1 Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] enforcer started Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] start command handler Jan 7 13:34:27
Scripting ods-enforcerd: [engine] start workers Jan 7 13:34:27
Scripting ods-enforcerd: [cmdhandler] start Jan 7 13:34:27 Scripting
ods-enforcerd: [autostart_cmd] autostart Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] schedule task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now Jan 7
13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt]
for policies Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
signal now Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
schedule task [enforce] for next zone Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] signal now Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] taking a break Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]]: report for duty Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] signal now Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]] start working Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]]: perform task [enforce] for next zone Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty Jan
7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now Jan 7
13:34:27 Scripting ods-enforcerd: SELECT zone.id, zone.rev,
zone.policyId, zone.name, zone.signconfNeedsWriting,
zone.signconfPath, zone.nextChange, zone.ttlEndDs, zone.ttlEndDk,
zone.ttlEndRs, zone.rollKskNow, zone.rollZskNow, zone.rollCskNow,
zone.inputAdapterType, zone.inputAdapterUri, zone.outputAdapterType,
zone.outputAdapterUri, zone.nextKskRoll, zone.nextZskRoll, zone.nextCskRoll FROM zone Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] start working Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: perform task [hsmkeygen] for all policies Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies [duration: 0] Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all] generating keys Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange
, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] no alarm set Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] start working Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: perform task [resalt] for policies Jan 7 13:34:27 Scripting ods-enforcerd: [worker[4]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidi
tyDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.id = ?
Post by Bas van den Dikkenberg
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.denialType = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
test.local Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer]
updatePolicy: policyName: LAB Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [policy_resalt_task] policies
have been updated Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]
finished working Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
schedule task [resalt] for policies Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] SIGALRM set Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[3]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 6 times: [
SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?] Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 2 times: [
SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?] Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
processing test.local with policyName LAB Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
processing key a91529a6115e99a514197aca707e39b9 4 Jan 7 13:34:27
Scripting ods-enforcerd: [enforcer] updateZone: processing key 549bf53b44b04b19a22d7b208f1885c3 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
processing key 6738b5dcea086c30106fdf89c7502a10 4 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DS in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 RRSIGDNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer]
updateZone: processing key c6d70fba0fb270e07dd24e9bf9fa7731 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
processing key 4ad5c47d20fb2a256bc427dccae2f580 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 4ad5c47d20fb2a256bc427dccae2f580 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
[hsm_key_factory_generate_all_task] generate for all policies done Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]] finished working Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty Jan
segfault at 7f2b6c2c2ff8 ip 00007f2b7046829c sp 00007f2b6c2c2ff0 error
6 in libc-2.23.so[7f2b703e7000+1bf000]
Van: Bas van den Dikkenberg
Verzonden: zaterdag 7 januari 2017 12:21
Onderwerp: segfault error 6 in libc-2.23.so
Hello,
[ 267.837057] ods-enforcerd[2414]: segfault at 7fa32a56dff8 ip
00007fa32ef1429c sp 00007fa32a56dff0 error 6 in
libc-2.23.so[7fa32ee93000+1bf000]
Any one an idee
_______________________________________________
Opendnssec-user mailing list
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
(Berry) A.W. van Halderen
2017-01-08 20:41:21 UTC
Permalink
Post by Bas van den Dikkenberg
Oke i made output you requested,
But the output file is big 2mb so you download it here: https://www.hobby.nl/images/putty.log
Normally only a couple of KBs, which immediately shows the problem, but
a puzzle also. You can remove it if you want, I've downloaded it.
Unfortunately the executionable has been stripped of debugging information
which makes it harder.

\Berry
Post by Bas van den Dikkenberg
Bas
-----Oorspronkelijk bericht-----
Verzonden: zondag 8 januari 2017 14:30
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so
Which version are you running? I guess an 2.x version..
gdb ods-enforcerd
run -d
It will then probably crash and you can get more information using either
bt
Or more extensive with
thread apply all bt
Crashes in libc are mostly memory-allocation problems related, so we like to hear those.
\Berry
Post by Bas van den Dikkenberg
Jan 7 13:34:27 Scripting ods-enforcerd: [cmdhandler] create socket
[file] create and chown /run/opendnssec with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [file]
create and chown /run/opendnssec/enforcer.sock with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [file]
create and chown /var/lib/opendnssec/enforcer with user=4294967295
group=4294967295 Jan 7 13:34:27 Scripting ods-enforcerd: [engine]
drop privileges Jan 7 13:34:27 Scripting ods-enforcerd: [engine]
running as pid 9430 Jan 7 13:34:27 Scripting ods-enforcerd: create
worker[1] Jan 7 13:34:27 Scripting ods-enforcerd: create worker[2]
Jan 7 13:34:27 Scripting ods-enforcerd: create worker[3] Jan 7
13:34:27 Scripting ods-enforcerd: create worker[4] Jan 7 13:34:27
Scripting ods-enforcerd: [util] writing pid 9430 to pidfile
[file] open file file=/run/opendnssec/enforcerd.pid mode=writing Jan
7 13:34:27 Scripting ods-enforcerd: [file] openfile
/run/opendnssec/enforcerd.pid count 1 Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] enforcer started Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] start command handler Jan 7 13:34:27
Scripting ods-enforcerd: [engine] start workers Jan 7 13:34:27
Scripting ods-enforcerd: [cmdhandler] start Jan 7 13:34:27 Scripting
ods-enforcerd: [autostart_cmd] autostart Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] schedule task [hsmkeygen] for all policies
Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now Jan 7
13:34:27 Scripting ods-enforcerd: [scheduler] schedule task [resalt]
for policies Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
signal now Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
schedule task [enforce] for next zone Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] signal now Jan 7 13:34:27 Scripting
ods-enforcerd: [engine] taking a break Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]]: report for duty Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] signal now Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]] start working Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[1]]: perform task [enforce] for next zone Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty Jan
7 13:34:27 Scripting ods-enforcerd: [scheduler] signal now Jan 7
13:34:27 Scripting ods-enforcerd: SELECT zone.id, zone.rev,
zone.policyId, zone.name, zone.signconfNeedsWriting,
zone.signconfPath, zone.nextChange, zone.ttlEndDs, zone.ttlEndDk,
zone.ttlEndRs, zone.rollKskNow, zone.rollZskNow, zone.rollCskNow,
zone.inputAdapterType, zone.inputAdapterUri, zone.outputAdapterType,
zone.outputAdapterUri, zone.nextKskRoll, zone.nextZskRoll, zone.nextCskRoll FROM zone Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]] start working Jan 7 13:34:27 Scripting ods-enforcerd: [worker[2]]: perform task [hsmkeygen] for all policies Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all_task] generate for all policies [duration: 0] Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate_all] generating keys Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChan
ge, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler] no alarm set Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]] start working Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]: perform task [resalt] for policies Jan 7 13:34:27 Scripting ods-enforcerd: [worker[4]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesVali
dityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.id = ?
Post by Bas van den Dikkenberg
Post by Bas van den Dikkenberg
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policy.id, policy.rev, policy.name, policy.description, policy.signaturesResign, policy.signaturesRefresh, policy.signaturesJitter, policy.signaturesInceptionOffset, policy.signaturesValidityDefault, policy.signaturesValidityDenial, policy.signaturesValidityKeyset, policy.signaturesMaxZoneTtl, policy.denialType, policy.denialOptout, policy.denialTtl, policy.denialResalt, policy.denialAlgorithm, policy.denialIterations, policy.denialSaltLength, policy.denialSalt, policy.denialSaltLastChange, policy.keysTtl, policy.keysRetireSafety, policy.keysPublishSafety, policy.keysShared, policy.keysPurgeAfter, policy.zonePropagationDelay, policy.zoneSoaTtl, policy.zoneSoaMinimum, policy.zoneSoaSerial, policy.parentRegistrationDelay, policy.parentPropagationDelay, policy.parentDsTtl, policy.parentSoaTtl, policy.parentSoaMinimum, policy.passthrough FROM policy WHERE policy.denialType = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
test.local Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer]
updatePolicy: policyName: LAB Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [policy_resalt_task] policies
have been updated Jan 7 13:34:27 Scripting ods-enforcerd: [worker[3]]
finished working Jan 7 13:34:27 Scripting ods-enforcerd: [scheduler]
schedule task [resalt] for policies Jan 7 13:34:27 Scripting
ods-enforcerd: [scheduler] SIGALRM set Jan 7 13:34:27 Scripting
ods-enforcerd: [worker[3]]: report for duty Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 6 times: [
SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?] Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: message repeated 2 times: [
SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?] Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT hsmKey.id, hsmKey.rev, hsmKey.policyId, hsmKey.locator, hsmKey.state, hsmKey.bits, hsmKey.algorithm, hsmKey.role, hsmKey.inception, hsmKey.isRevoked, hsmKey.keyType, hsmKey.repository, hsmKey.backup FROM hsmKey WHERE hsmKey.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
processing test.local with policyName LAB Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyDependency.id, keyDependency.rev, keyDependency.zoneId, keyDependency.fromKeyDataId, keyDependency.toKeyDataId, keyDependency.type FROM keyDependency WHERE keyDependency.zoneId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
processing key a91529a6115e99a514197aca707e39b9 4 Jan 7 13:34:27
Scripting ods-enforcerd: [enforcer] updateZone: processing key 549bf53b44b04b19a22d7b208f1885c3 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 549bf53b44b04b19a22d7b208f1885c3 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
processing key 6738b5dcea086c30106fdf89c7502a10 4 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DS in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May KSK 6738b5dcea086c30106fdf89c7502a10 RRSIGDNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer]
updateZone: processing key c6d70fba0fb270e07dd24e9bf9fa7731 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK c6d70fba0fb270e07dd24e9bf9fa7731 RRSIG in state unretentive transition to hidden?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
processing key 4ad5c47d20fb2a256bc427dccae2f580 1 Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone: May ZSK 4ad5c47d20fb2a256bc427dccae2f580 DNSKEY in state omnipresent transition to unretentive?
Jan 7 13:34:27 Scripting ods-enforcerd: [enforcer] updateZone Policy
says we can (1/3) Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyData.id, keyData.rev, keyData.zoneId, keyData.hsmKeyId, keyData.algorithm, keyData.inception, keyData.role, keyData.introducing, keyData.shouldRevoke, keyData.standby, keyData.activeZsk, keyData.publish, keyData.activeKsk, keyData.dsAtParent, keyData.keytag, keyData.minimize FROM keyData WHERE keyData.id = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT keyState.id, keyState.rev, keyState.keyDataId, keyState.type, keyState.state, keyState.lastChange, keyState.minimize, keyState.ttl FROM keyState WHERE keyState.keyDataId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT policyKey.id, policyKey.rev, policyKey.policyId, policyKey.role, policyKey.algorithm, policyKey.bits, policyKey.lifetime, policyKey.repository, policyKey.standby, policyKey.manualRollover, policyKey.rfc5011, policyKey.minimize FROM policyKey WHERE policyKey.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role KSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
Jan 7 13:34:27 Scripting ods-enforcerd: [hsm_key_factory_generate]
repository SoftHSM role ZSK Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM hsmKey WHERE hsmKey.policyId = ? AND hsmKey.state = ? AND hsmKey.bits = ? AND hsmKey.algorithm = ? AND hsmKey.role = ? AND hsmKey.isRevoked = ? AND hsmKey.keyType = ? AND hsmKey.repository = ?
Jan 7 13:34:27 Scripting ods-enforcerd: SELECT COUNT(*) FROM zone WHERE zone.policyId = ?
[hsm_key_factory_generate_all_task] generate for all policies done Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]] finished working Jan
7 13:34:27 Scripting ods-enforcerd: [worker[2]]: report for duty Jan
segfault at 7f2b6c2c2ff8 ip 00007f2b7046829c sp 00007f2b6c2c2ff0 error
6 in libc-2.23.so[7f2b703e7000+1bf000]
Van: Bas van den Dikkenberg
Verzonden: zaterdag 7 januari 2017 12:21
Onderwerp: segfault error 6 in libc-2.23.so
Hello,
[ 267.837057] ods-enforcerd[2414]: segfault at 7fa32a56dff8 ip
00007fa32ef1429c sp 00007fa32a56dff0 error 6 in
libc-2.23.so[7fa32ee93000+1bf000]
Any one an idee
_______________________________________________
Opendnssec-user mailing list
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user
--
N: (Berry) A.W. van Halderen
O: NLnet Labs
W: http://www.nlnetlabs.nl/
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
(Berry) A.W. van Halderen
2017-01-08 20:51:25 UTC
Permalink
Post by (Berry) A.W. van Halderen
Post by Bas van den Dikkenberg
Oke i made output you requested,
But the output file is big 2mb so you download it here: https://www.hobby.nl/images/putty.log
Normally only a couple of KBs, which immediately shows the problem, but
a puzzle also. You can remove it if you want, I've downloaded it.
Unfortunately the executionable has been stripped of debugging information
which makes it harder.
I also see you are running 2.0.2. Please upgrade to version 2.0.3, although
probably not related, it is good to rule out and you avoid other problems
in general.

\Berry
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
Bas van den Dikkenberg
2017-01-08 21:15:45 UTC
Permalink
Theni found a another bug :-D

The packages that's is deliverd as version 2.0.3 from the repo https://launchpad.net/~pkg-opendnssec/+archive/ubuntu/ppa/+packages for Ubuntu xenial is version 2.0.2 acording to verison.m4 file in the sources

Give me few moment to rebuild the packages

Bas


-----Oorspronkelijk bericht-----
Van: (Berry) A.W. van Halderen [mailto:***@nlnetlabs.nl]
Verzonden: zondag 8 januari 2017 21:51
Aan: Bas van den Dikkenberg <***@Dikkenberg.net>
CC: opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so
Post by (Berry) A.W. van Halderen
Post by Bas van den Dikkenberg
Oke i made output you requested,
https://www.hobby.nl/images/putty.log
Normally only a couple of KBs, which immediately shows the problem,
but a puzzle also. You can remove it if you want, I've downloaded it.
Unfortunately the executionable has been stripped of debugging
information which makes it harder.
I also see you are running 2.0.2. Please upgrade to version 2.0.3, although probably not related, it is good to rule out and you avoid other problems in general.

\Berry
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
Bas van den Dikkenberg
2017-01-08 22:13:55 UTC
Permalink
I rebuild the packages with 2.0.3 source build the result is the same:
You can see the output:
www.hobby.nl/images/putty2.log


-----Oorspronkelijk bericht-----
Van: Opendnssec-user [mailto:opendnssec-user-***@lists.opendnssec.org] Namens Bas van den Dikkenberg
Verzonden: zondag 8 januari 2017 22:16
Aan: (Berry) A.W. van Halderen <***@nlnetlabs.nl>
CC: opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so

Theni found a another bug :-D

The packages that's is deliverd as version 2.0.3 from the repo https://launchpad.net/~pkg-opendnssec/+archive/ubuntu/ppa/+packages for Ubuntu xenial is version 2.0.2 acording to verison.m4 file in the sources

Give me few moment to rebuild the packages

Bas


-----Oorspronkelijk bericht-----
Van: (Berry) A.W. van Halderen [mailto:***@nlnetlabs.nl]
Verzonden: zondag 8 januari 2017 21:51
Aan: Bas van den Dikkenberg <***@Dikkenberg.net>
CC: opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so
Post by (Berry) A.W. van Halderen
Post by Bas van den Dikkenberg
Oke i made output you requested,
https://www.hobby.nl/images/putty.log
Normally only a couple of KBs, which immediately shows the problem,
but a puzzle also. You can remove it if you want, I've downloaded it.
Unfortunately the executionable has been stripped of debugging
information which makes it harder.
I also see you are running 2.0.2. Please upgrade to version 2.0.3, although probably not related, it is good to rule out and you avoid other problems in general.

\Berry
--
N: (Berry) A.W. van Halderen
E: ***@nlnetlabs.nl
O: NLnet Labs
W: http://www.nlnetlabs.nl/
Yuri Schaeffer
2017-01-09 09:40:34 UTC
Permalink
Hi Bas,
Post by Bas van den Dikkenberg
www.hobby.nl/images/putty2.log
Thanks. Additionally can you send me the executable you compiled
(ods-enforcerd)?

And if you can, rebuild opendnssec with debugging symbols please. Then
GDB will give a much more helpful output.

make clean; make CFLAGS="-g -O0"

//Yuri
Bas van den Dikkenberg
2017-01-09 11:57:05 UTC
Permalink
You can download the deb files from my ppa:
https://launchpad.net/~bas-dikkenberg/+archive/ubuntu/opendnssec


-----Oorspronkelijk bericht-----
Van: Opendnssec-user [mailto:opendnssec-user-***@lists.opendnssec.org] Namens Yuri Schaeffer
Verzonden: maandag 9 januari 2017 10:41
Aan: opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so

Hi Bas,
Post by Bas van den Dikkenberg
www.hobby.nl/images/putty2.log
Thanks. Additionally can you send me the executable you compiled (ods-enforcerd)?

And if you can, rebuild opendnssec with debugging symbols please. Then GDB will give a much more helpful output.

make clean; make CFLAGS="-g -O0"

//Yuri
Yuri Schaeffer
2017-01-09 13:32:09 UTC
Permalink
Post by Bas van den Dikkenberg
https://launchpad.net/~bas-dikkenberg/+archive/ubuntu/opendnssec
I've download [1]. ( I assume you use 64bit, sqlite ). Looking at the
filename you recompiled with debugging symbols?

But the enforcer executable in that archive is stripped of debugging
symbols according to the file utility. Also, after recompilation,
addresses in your stacktrace do no longer correspond to your executable.
So I either need a new stacktrace* or the old executable.

//Yuri

[1]
https://launchpad.net/~bas-dikkenberg/+archive/ubuntu/opendnssec/+build/11835631/+files/opendnssec-enforcer-sqlite3_2.0.3a-3debug+deb.bvdd~xenial_amd64.deb

* A new stacktrace /with/ debugging + executable is preferred.
Yuri Schaeffer
2017-01-09 13:36:29 UTC
Permalink
Hi Bas,

Another question, what HSM do you use? SoftHSM2 by any chance?

//Yuri
Post by Bas van den Dikkenberg
https://launchpad.net/~bas-dikkenberg/+archive/ubuntu/opendnssec
-----Oorspronkelijk bericht-----
Verzonden: maandag 9 januari 2017 10:41
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so
Hi Bas,
Post by Bas van den Dikkenberg
www.hobby.nl/images/putty2.log
Thanks. Additionally can you send me the executable you compiled (ods-enforcerd)?
And if you can, rebuild opendnssec with debugging symbols please. Then GDB will give a much more helpful output.
make clean; make CFLAGS="-g -O0"
//Yuri
Bas van den Dikkenberg
2017-01-09 14:01:34 UTC
Permalink
Yes i run softhsm2
And i am running with mysql not sqlite

-----Oorspronkelijk bericht-----
Van: Yuri Schaeffer [mailto:***@nlnetlabs.nl]
Verzonden: maandag 9 januari 2017 14:36
Aan: Bas van den Dikkenberg <***@Dikkenberg.net>; opendnssec-***@lists.opendnssec.org
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so

Hi Bas,

Another question, what HSM do you use? SoftHSM2 by any chance?

//Yuri
Post by Bas van den Dikkenberg
https://launchpad.net/~bas-dikkenberg/+archive/ubuntu/opendnssec
-----Oorspronkelijk bericht-----
Verzonden: maandag 9 januari 2017 10:41
Onderwerp: Re: [Opendnssec-user] segfault error 6 in libc-2.23.so
Hi Bas,
Post by Bas van den Dikkenberg
www.hobby.nl/images/putty2.log
Thanks. Additionally can you send me the executable you compiled (ods-enforcerd)?
And if you can, rebuild opendnssec with debugging symbols please. Then GDB will give a much more helpful output.
make clean; make CFLAGS="-g -O0"
//Yuri
PGNet Dev
2017-01-08 20:58:35 UTC
Permalink
Missed the early part of this particular discussion, but just an fyi, in case it's of help :

With self-built ODS2/head, I'd seen segfaults in libc on launch as well, for both signerd/enforcerd.

I never got as far as GDB -- logs showed my issue, wrong/changed perms on the PID dir, e.g.

...
Jan 08 10:55:16 test.int systemd[1]: Starting OpenDNSSEC v2 Signer daemon...
Jan 08 10:55:16 test.int systemd[1]: ods-signerd.service: PID file /var/run/opendnssec/signerd.pid not readable (yet?) after start: No such file or directory
Jan 08 10:55:16 test.int ods-signerd[11212]: [cmdhandler] unable to create cmdhandler: bind() failed: No such file or directory
Jan 08 10:55:16 test.int ods-signerd[11212]: [engine] setup failed: Command handler error
Jan 08 10:55:16 test.int ods-signerd[11212]: Segmentation fault
Jan 08 10:55:16 test.int ods-signerd[11212]: :
Jan 08 10:55:16 test.int ods-signerd[11212]: unknown
Jan 08 10:55:16 test.int ods-signerd[11212]: unknown
Jan 08 10:55:16 test.int ods-signerd[11212]: unknown
Jan 08 10:55:16 test.int ods-signerd[11212]: unknown
Jan 08 10:55:16 test.int ods-signerd[11212]: __libc_start_main
Jan 08 10:55:16 test.int ods-signerd[11212]: unknown
Jan 08 10:55:16 test.int sh[11211]: Segmentation fault:
Jan 08 10:55:16 test.int sh[11211]: unknown
Jan 08 10:55:16 test.int sh[11211]: unknown
Jan 08 10:55:16 test.int sh[11211]: unknown
Jan 08 10:55:16 test.int sh[11211]: unknown
Jan 08 10:55:16 test.int sh[11211]: __libc_start_main
Jan 08 10:55:16 test.int sh[11211]: unknown
Jan 08 10:55:16 test.int systemd[1]: ods-signerd.service: Daemon never wrote its PID file. Failing.
Jan 08 10:55:16 test.int systemd[1]: Failed to start OpenDNSSEC v2 Signer daemon.
Jan 08 10:55:16 test.int systemd[1]: ods-signerd.service: Unit entered failed state.
Jan 08 10:55:16 test.int systemd[1]: ods-signerd.service: Failed with result 'resources'.
Jan 08 10:55:18 test.int systemd-coredump[11213]: Process 11212 (ods-signerd) of user 0 dumped core.
...

and similar for enforcerd.

For my

cat /etc/systemd/system/ods-signer.service
...
[Service]
Type=forking
PIDFile=/var/run/opendnssec/signerd.pid
...

cat /etc/systemd/system/ods-enforcer.service
...
[Service]
Type=forking
PIDFile=/var/run/opendnssec/enforcerd.pid
...

I'd manually created, chmod'd & chown'd the pid dir, but at some point something (maybe me, inadvertently?) had changed the perms :-/

Simple fix

cat /etc/tmpfiles.d/opendnssec.conf
...
+ D /var/run/opendnssec 0755 opendnssec opendnssec -
...
systemd-tmpfiles --create /etc/tmpfiles.d/opendnssec.conf

worked around the problem here.

I say workaround, rather than fix, as, of course, segfault-ing for lack of a PID file/dir is not a sane exit ...
Yuri Schaeffer
2017-01-13 11:14:44 UTC
Permalink
For the record: We have found the issue and committed a fix. Later today
we will release OpenDNSSEC 2.0.4 which will include this fix.

//Yuri

Loading...