Troubleshooting

Error

Diagnosis

error: [example.com.] DNSSEC, failed to initialize signing context (PKCS #11 token not available)

Verify that there is connectivity between KNOT and Utimaco HSM.

Also verify that the Slot is available to KNOT.

error: [example.com.] failed to parse zone file '/var/lib/knot/example.com.zone' (operation not permitted)

Make sure that the zone file has all the entries in correct format and there is no unallowed entries in it.

Irrespective of whichever slot has been initialized in p11tool2 command, knot dns will only use slot 0 for signing key generation..

This is expected behavior as knot dns will only use slot 0

List of errror and its diagnosis