June 2018
Intermediate to advanced
368 pages
11h 1m
English
It is not a requirement that you periodically roll over your keys. It is often suggested. In most discussions of DNSSEC, they almost invariably assume that you will be rolling their keys.
When rolling over your ZSK, you don't need to regenerate your DS record, and, thus, no reinsertion into the parent domain is required.
You will need to regenerate your DS when you rollover your KSK, because the associated hash of your KSK in the DS will change.
Read now
Unlock full access