On Fri, 14 Jan 2022 13:25:35 +0000, Brett Carr <[email protected]> wrote:
>This is the expected state, this TLD is mid transition when this is complete >the currently unused DS and DNSKEY will be used for signing. This is >pre-publication of the new data. Thanks for that inforation (and also to Ondrej & Viktor). My learning experience for today is that a DS can point at a standby, but as yet unused, KSK. Re-reading bits of rfc6781, this now makes sense to me. Out of interest, was it intentional that the authoratitives were returning NXDOMAIN for dnsc.nic.law, dnsa.nic.law, dns1.nic.law & dns3.nic.law from 11 January for a day or two whilst they were still listed in the root delegation? https://www.zonemaster.fr/result/9e9d3f9ca39a9e6e Best wishes, Matthew _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations
