Hello Sebastian, > http://dnsviz.net/d/6v6.de/W9AmtA/dnssec/ > > Looking at the graph the new KSK (54879) is not signing anything right > now. Shouldn't it sign the DNSKEY records of the ZSKs so that the > chain stays intact when the DS record changed at the parent zone?
You are reading the graph wrong. The new KSK is signing the DNSKEY RRset. See: dig @ns1.karotte.org 6v6.de DNSKEY +dnssec Daniel -- https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users
