opendnssec-enforcer-sqlite3 - tool to prepare DNSSEC keys (sqlite3 backend)

OpenDNSSEC is a complete DNSSEC zone signing system which is very
easy to use with stability and security in mind.  There are a lot of
details in signing zone files with DNSSEC and OpenDNSSEC covers most
of it.
OpenDNSSEC Enforcer, which is a tool to make sure that there are
enough keys for all of the zones, and take the policy and key
information from the KASP database and turn it into an xml file that
the signer can use.
The package contains OpenDNSSEC Enforcer binaries with sqlite3 backend.


opendnssec-enforcer-sqlite3_2.1.3-3_i386.deb 2.1.3 i386 Ubuntu Universe
Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install opendnssec-enforcer-sqlite3 deb package:
    # sudo apt-get install opendnssec-enforcer-sqlite3




2019-03-10 - Mathieu Mirmont <>
opendnssec (1:2.1.3-3) unstable; urgency=medium
* po/pt.po: Add Portuguese translation (Closes: #923569)
* po/nl.po: Add Dutch translation (Closes: #924102)
* po/fr.po: Add French translation (Closes: #924055)
* Fix build warnings and possible bugs
2019-02-26 - Mathieu Mirmont <>
opendnssec (1:2.1.3-2) unstable; urgency=medium
* po/de.po: Add German translation (Closes: #922638)
* gitlab-ci.yml: Check for missing debconf-updatepo
* po/templates.po: Update the templates.pot file
* opendnssec-*.service: Fix service files
* opendnssec-*.init: use do_restart_prepare from init-d-script
2019-02-06 - Mathieu Mirmont <>
opendnssec (1:2.1.3-1) unstable; urgency=medium
[ Timo Aaltonen ]
* rules: Fix db conversion script install dir. (Closes: #864614)
* rules: Use libsofthsm2. (Closes: #868292)
* Remove empty maintscripts.
* control: Update VCS urls.
* control: Priority should be optional, not extra.
* compat, control, rules: Bump debhelper to 10.
* lintian-overrides: Updated.
* control: Bump policy to 4.3.0.
* control: Add myself to uploaders, drop Ondřej.
[ Mathieu Mirmont ]
* upstream/signing-key.asc: Update the keys
* Fix the enforcer and signer init scripts (Closes: #868368)
* Add support for po-debconf
* Fix the ods-enforcer.8 man page
* gitlab-ci.yml: Add a GitLab CI file
*{inst,rm}: Add --debconf-ok to ucf
* ods-kasp.5.gz: Suppress the lintian warning
* ods-kaspcheck.1: Remove unused manpage
* ods-kasp2html.1: Add a simple man page
* Strip the build directory from the doxygen docs
* Remove bashism
* opendnssec-common.postrm: Prevent multiple deluser
* opendnssec-common.examples: There are no examples
* signconf.xml.patch: Remove obsolete file
* opendnssec-common.config: Migration warning only if migrating
* rules: Use dh_missing for --fail-missing
* Shellcheck fixes
* control: opendnssec-doc is Multi-Arch: foreign
* Fix service crash after installation (Closes: #859419)
* control: New maintainer: yours truly
2019-01-08 - Timo Aaltonen <>
opendnssec (1:2.1.3-0.3) unstable; urgency=medium
* Non-maintainer upload.
* control: Update the maintainer address. (Closes: #899628)
2017-09-21 - Timo Aaltonen <>
opendnssec (1:2.1.3-0.2) unstable; urgency=medium
* Non-maintainer upload.
* rules: Drop handling old dbg packages from dh_installdocs override.
(Closes: #876277)
2017-09-19 - Timo Aaltonen <>
opendnssec (1:2.1.3-0.1) unstable; urgency=medium
* Non-maintainer upload.
* New upstream release. (Closes: #869091, #870072) (LP: #1703836)
- refresh patches
* enforcer-*.install: ods-ksmutil was removed, drop from here too.
* source/local-options: Ignore files not on the tarball.
2017-05-08 - Ondřej Surý <>
opendnssec (1:2.0.4-3) unstable; urgency=medium
* Fix reading the tmpfiles (Thanks Michael Biebl for catching that)
(Closes: #852059)
* Add /var/lib/opendnssec/{signer,enforcer} to the list of managed
directories (Closes: #859418)
2017-02-01 - Ondřej Surý <>
opendnssec (1:2.0.4-2) unstable; urgency=high
* Also add empty postinst and postrm maintainer scripts to
opendnssec-enforcer-mysql package to allow upgrades from jessie
(Closes: #848111)
2017-01-18 - Ondřej Surý <>
opendnssec (1:2.0.4-1) unstable; urgency=medium
* Drop (<< 5.7) from libmysqlclient-dev B-D to allow builds on Ubuntu
* New upstream version 2.0.4
* Remove OpenSSL 1.1 patch as support was merged upstream
2017-01-09 - Ondřej Surý <>
opendnssec (1:2.0.3+-1) unstable; urgency=medium
* Imported Upstream version 2.0.3 (again from upstream tarball,
the previous tarball seems to be botched somehow for unknown

