Maintaining DS keys after initial setup (CDS/CDNSKEY)
One problem with DNSSEC can occur when you're rolling their KSK: They need to update their DS record in the parent zone. There is no standardized way to do this yet. Worse, it can involve multiple parties who may not even be known to one another.
With CDS/CDNSKEY, the DNS operator can control what they want to see in the parent zone for their DS records via CDS or the CDNSKEY RRs they publish within their own zone.
At the time of writing, no Registries or TLDs actively support CDNSKEY, but there are a few test beds in progress so I expect to see this being deployed someday. Once this happens, one of the last big caveats of DNSSEC will become a lot more managaeable.
Also see: https://tools.ietf.org/id/draft-ietf-dnsop-maintain-ds-05.html ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access