June 2018
Intermediate to advanced
368 pages
11h 1m
English
While it is not mandatory to rollover your keys (as one tech reviewer put it, "How often do you roll over your ssh keys?"). Keys that last for ever were specifically prohibited in earlier operational definitions of DNSSEC, and many tutorials and literature around it still specify a rollover interval. But the operational practices have since evolved and it is now permissible to create keys that do not expire. Consider this:
"In general, the available key length sets an upper limit on the key effectivity period. For all practical purposes, it is sufficient to define the key effectivity period based on purely operational requirements and match the key length to that value. Ignoring the operational perspective, a reasonable ...
Read now
Unlock full access