ndns-add-rr enables special handling for self-signed KSK
In current design, all self-signed certificate will be resigned by the current zone's dsk if added as a file. Therefore, it is not possible to add root certificate to the database. Hence, an option is added to suppress the resigning process.
Updated by Alex Afanasyev almost 6 years ago
First, i wouldn't call it "root" certificate. Second, I would, actually, do the opposite. By default, anything that is imported from file is getting inserted as is. If some flag is specified (I think it could be
--dsk), then the tool will do the signing.