Commit 0822504141 for bind

commit 08225041419b4f28740cebde17edf2ef8c00d667
Author: Nicki Křížek <nicki@isc.org>
Date:   Fri Oct 2 10:03:42 2026 +0000

    Remove the autosign public-only key's private file last

    dnssec-keygen only avoids the key tags of keys that have a private key
    file. The KSKs generated after the private file of the public-only ZSK
    was removed could thus share its key tag, or overwrite its key file
    outright.

    Assisted-by: Claude:claude-opus-5-5

diff --git a/bin/tests/system/autosign/ns1/keygen.sh b/bin/tests/system/autosign/ns1/keygen.sh
index 830728aa98..3b429e7579 100644
--- a/bin/tests/system/autosign/ns1/keygen.sh
+++ b/bin/tests/system/autosign/ns1/keygen.sh
@@ -29,11 +29,14 @@ zskunpub=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q -G $zone)
 zsksby=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q -A none $zone)
 zskactnowpub1d=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q -A now -P +1d $zone)
 zsknopriv=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q $zone)
-rm $zsknopriv.private

 ksksby=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q -P now -A now -fk $zone)
 kskrev=$($KEYGEN -3 -a ${DEFAULT_ALGORITHM} -q -R now -fk $zone)

+# Only remove the private key once all keys are generated: dnssec-keygen
+# only avoids key tag collisions with keys that have a private key file.
+rm $zsknopriv.private
+
 keyfile_to_static_ds $ksksby >trusted.conf
 cp trusted.conf ../ns2/trusted.conf
 cp trusted.conf ../ns3/trusted.conf