Impossible to use DNSSec using recent kernel

Discussion in 'ISPConfig 3 Priority Support' started by pzajda, Oct 28, 2022.

  1. pzajda

    pzajda Member HowtoForge Supporter

    Hello,

    I use ISPConfig on Debian Bullseye, Debian kernel version 5.10.0-19-amd64.
    I tried to enable DNSSEC for a zone but I have the following message in cron.log:
    DNSSEC ERROR: We are low on entropy. Not generating new Keys for gansta93.com. Please consider installing package haveged.

    Haveged is already installed on this server.
    cat /proc/sys/kernel/random/entropy_avail always returns 256

    After some search, it looks this value is the one now used: https://superuser.com/questions/173...y-input-with-debian11-kernel-debian-5-10-0-17
    And this makes impossible to enable DNSSEC for a DNS zone using ISPConfig, except if I made a mistake of course.

    Should I create an issue on the ISPConfig gitlab or is there something I could try to be able to enable DNSSEC?
     
  2. Th0m

    Th0m ISPConfig Developer Staff Member ISPConfig Developer

  3. pzajda

    pzajda Member HowtoForge Supporter

    I might have searched better on the forum...
    Thanks a lot, I understand now.
    And if I am right, the fix will be available in the next stable version?
    For now I will manually modify the line to make same modifications the commit specified in the post you linked makes.
     
  4. Th0m

    Th0m ISPConfig Developer Staff Member ISPConfig Developer

    Yes.
     
    pzajda likes this.

Share This Page