Commit 35a4cf3953 for bind
commit 35a4cf3953eeafaf4a8cb56ce1b9e7a184d5cde4
Author: Nicki Křížek <nicki@isc.org>
Date: Fri Oct 2 10:03:42 2026 +0000
Pass the algorithm to rndc dnssec -checkds in rollover steps
During an algorithm rollover, the KSKs of the two algorithms may share
a key tag. named then refuses to pick one of them, the DS is never
marked as published or withdrawn, and the rollover step times out.
Assisted-by: Claude:claude-opus-5-5
diff --git a/bin/tests/system/isctest/kasp.py b/bin/tests/system/isctest/kasp.py
index da9292b4c9..050de2a384 100644
--- a/bin/tests/system/isctest/kasp.py
+++ b/bin/tests/system/isctest/kasp.py
@@ -1366,12 +1366,14 @@ def check_rollover_step(server, config, policy, step):
# The DS can be introduced. We ignore any parent registration delay,
# so set the DS publish time to now.
- server.rndc(f"dnssec -checkds -key {key.tag} published {zone}")
+ alg = key.algorithm.name
+ server.rndc(f"dnssec -checkds -key {key.tag} -alg {alg} published {zone}")
if ds_swap and kp.metadata["DSState"] == "unretentive":
# The DS can be withdrawn. We ignore any parent registration
# delay, so set the DS withdraw time to now.
- server.rndc(f"dnssec -checkds -key {key.tag} withdrawn {zone}")
+ alg = key.algorithm.name
+ server.rndc(f"dnssec -checkds -key {key.tag} -alg {alg} withdrawn {zone}")
if check_keytimes_flag:
check_keytimes(keys, expected)