* Daniel Stirnimann <[email protected]> [2018-10-24 10:28]:
> Hello Sebastian,
> 
> > http://dnsviz.net/d/6v6.de/W9AmtA/dnssec/
> > 
> > Looking at the graph the new KSK (54879) is not signing anything right
> > now. Shouldn't it sign the DNSKEY records of the ZSKs so that the
> > chain stays intact when the DS record changed at the parent zone?
> 
> You are reading the graph wrong. The new KSK is signing the DNSKEY
> RRset. See:
> 
> dig @ns1.karotte.org 6v6.de DNSKEY +dnssec

Yeah, it was a brain fart together with the IMO suboptimal graph
display at dnsviz. Sorry for the noise.

Best Regards

Sebastian

-- 
GPG Key: 0x58A2D94A93A0B9CE (F4F6 B1A3 866B 26E9 450A  9D82 58A2 D94A 93A0 B9CE)
'Are you Death?' ... IT'S THE SCYTHE, ISN'T IT? PEOPLE ALWAYS NOTICE THE SCYTHE.
            -- Terry Pratchett, The Fifth Elephant
-- 
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users

Reply via email to