On Fri, 14 Jan 2022 13:25:35 +0000, Brett Carr <[email protected]>
wrote:

>This is the expected state, this TLD is mid transition when this is complete 
>the currently unused DS and DNSKEY will be used for signing. This is 
>pre-publication of the new data.

Thanks for that inforation (and also to Ondrej & Viktor).  My learning
experience for today is that a DS can point at a standby, but as yet
unused, KSK.  Re-reading bits of rfc6781, this now makes sense to me.

Out of interest, was it intentional that the authoratitives were returning
NXDOMAIN for dnsc.nic.law, dnsa.nic.law, dns1.nic.law & dns3.nic.law from
11 January for a day or two whilst they were still listed in the root
delegation?

https://www.zonemaster.fr/result/9e9d3f9ca39a9e6e

Best wishes,
Matthew
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to