Hello Sebastian,

> http://dnsviz.net/d/6v6.de/W9AmtA/dnssec/
> 
> Looking at the graph the new KSK (54879) is not signing anything right
> now. Shouldn't it sign the DNSKEY records of the ZSKs so that the
> chain stays intact when the DS record changed at the parent zone?

You are reading the graph wrong. The new KSK is signing the DNSKEY
RRset. See:

dig @ns1.karotte.org 6v6.de DNSKEY +dnssec

Daniel
-- 
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

Reply via email to