diff --git a/bin/dnssec/dnssec-keygen.c b/bin/dnssec/dnssec-keygen.c index 65823b1cd3..996b3ac6a6 100644 --- a/bin/dnssec/dnssec-keygen.c +++ b/bin/dnssec/dnssec-keygen.c @@ -1223,18 +1223,7 @@ main(int argc, char **argv) { fatal("-k and -3 cannot be used together"); } - if (ctx.setpub || ctx.setact || ctx.setrev || ctx.setinact || - ctx.setdel || ctx.unsetpub || ctx.unsetact || - ctx.unsetrev || ctx.unsetinact || ctx.unsetdel || - ctx.setsyncadd || ctx.setsyncdel) - { - fatal("cannot use -k together with " - "-P, -A, -R, -I, or -D options " - "(use dnssec-settime on keys afterwards)"); - } - ctx.options |= DST_TYPE_STATE; - ctx.genonly = true; if (strcmp(ctx.policy, "default") == 0) { ctx.use_nsec3 = false; diff --git a/bin/tests/system/kasp/ns3/setup.sh b/bin/tests/system/kasp/ns3/setup.sh index 3549933642..6fc5c07a17 100644 --- a/bin/tests/system/kasp/ns3/setup.sh +++ b/bin/tests/system/kasp/ns3/setup.sh @@ -71,8 +71,8 @@ $KEYGEN -a RSASHA1 -b 2000 -L 1234 $zone > keygen.out.$zone.1 2>&1 $KEYGEN -a RSASHA1 -f KSK -L 1234 $zone > keygen.out.$zone.2 2>&1 zone="pregenerated.kasp" -$KEYGEN -k rsasha1 -l policies/kasp.conf $zone > keygen.out.$zone.1 2>&1 -$KEYGEN -k rsasha1 -l policies/kasp.conf $zone > keygen.out.$zone.2 2>&1 +$KEYGEN -G -k rsasha1 -l policies/kasp.conf $zone > keygen.out.$zone.1 2>&1 +$KEYGEN -G -k rsasha1 -l policies/kasp.conf $zone > keygen.out.$zone.2 2>&1 zone="rumoured.kasp" Tpub="now"