June 2018
Intermediate to advanced
368 pages
11h 1m
English
DS RRs are used to establish the chain-of-trust from the "." internet root all the way down to an eventual DNSSEC-signed hostname being queried.
Each DNSSEC-enabled zone has a Delegation Signing (DS) RR (RFC 3658) in its parent zone. The DS RR from the child contains a hash of the child's public KSK. It is placed into the parent zone where it is signed by the parent's ZSK. It is up to the child zone administrator to facilitate secure transfer of the DS into the parent zone. Some registries allow this via their own platforms (see sidebar), typically this operation is done via the child zone's registrar:

Read now
Unlock full access