I have read through RFC 4641 and I believe I understand the various key roll over procedures, but the RFC does not mention the scenario of adding the DS records to the parent before publishing and/or using the new KSKs. It is safe to pre-publish new DS records and once it has propagated to slave servers + it's original TTL, swap out the KSK and resign the DNSKEY RRset? -- Loren M. Lang [email protected] http://www.north-winds.org/
Public Key: ftp://ftp.north-winds.org/pub/lorenl_pubkey.asc Fingerprint: 10A0 7AE2 DAF5 4780 888A 3FA4 DCEE BB39 7654 DE5B
signature.asc
Description: Digital signature
_______________________________________________ bind-users mailing list [email protected] https://lists.isc.org/mailman/listinfo/bind-users

