test "$_checksig" -eq 0 && return 0
- retry_quiet 3 _check_signatures "DNSKEY" "dig.out.$DIR.test$n" "KSK" || return 1
+ _check_signatures "DNSKEY" "dig.out.$DIR.test$n" "KSK" || return 1
return 0
}
n=$((n+1))
echo_i "check DNSKEY rrset is signed correctly for zone ${ZONE} ($n)"
ret=0
- retry_quiet 3 _check_apex_dnskey || ret=1
+ retry_quiet 10 _check_apex_dnskey || ret=1
test "$ret" -eq 0 || echo_i "failed"
status=$((status+ret))
- # We retry the DNSKEY query for at most three seconds to avoid test
+ # We retry the DNSKEY query for at most ten seconds to avoid test
# failures due to timing issues. If the DNSKEY query check passes this
# means the zone is resigned and further apex checks (SOA, CDS, CDNSKEY)
# don't need to be retried quietly.