]> git.ipfire.org Git - thirdparty/knot-dns.git/commitdiff
doc: updated onlinesign section to current limitations
authorLibor Peltan <libor.peltan@nic.cz>
Sat, 13 Jan 2018 11:25:25 +0000 (12:25 +0100)
committerDaniel Salzman <daniel.salzman@nic.cz>
Fri, 2 Feb 2018 09:19:55 +0000 (10:19 +0100)
src/knot/modules/onlinesign/onlinesign.rst

index 0617b31d1d22ac550224d6246888316aa782e8ed..efb7e6093bebeb23abeb6cf25c737d645dbf8c97 100644 (file)
@@ -41,14 +41,12 @@ a DNSSEC validating resolver.
 
 * RRSIG records are synthesized for authoritative content of the zone.
 
-.. rubric:: Known issues:
-
-* The delegations are not signed correctly.
+* CDNSKEY and CDS records are generated as usual to publish valid Secure Entry Point.
 
-* Some CNAME records are not signed correctly.
+.. rubric:: Known issues:
 
-* The automatic policy-based key rotation does not work well, as the rotation
-  events are invoked just at server (re)load.
+* The `knotc zone-ksk-submitted` command does not work well and is discouraged.
+  The module must be reloaded afterwards.
 
 .. rubric:: Limitations: