[root@services:/etc/bind/master] # vim /etc/bind/master/nl/freshdot.nl/zone.db [root@services:/etc/bind/master] # zkt-signer -v -v -D /etc/bind/master/nl freshdot.nl. parsing zone "freshdot.nl." in dir "/etc/bind/master/nl/freshdot.nl" Check RFC5011 status ->not a rfc5011 zone, looking for a regular ksk rollover Check KSK status Check ZSK status Re-signing necessary: Zone file edited Writing key file "/etc/bind/master/nl/freshdot.nl/dnskey.db" Incrementing serial number in file "/etc/bind/master/nl/freshdot.nl/zone.db" Signing zone "freshdot.nl." Run cmd "cd /etc/bind/master/nl/freshdot.nl; /usr/sbin/dnssec-signzone -u -3 3796FE -C -g -o freshdot.nl. -e +1814400 zone.db K*.private 2>&1" Cmd dnssec-signzone return: "zone.db.signed" Signing completed after 0s.