On 13 jun 2014, at 13:52, Petr Spacek <[email protected]> wrote:
> I would expect that <KSK /> flag appears only after ds-seen command, i.e.
> when the key reaches ACTIVE state.
>
> It is intentional or is it a bug?
The KSK key rollover works by signing the DNSKEY RRset with all ready/active
keys (aka double sign), so this is intentional.
jakob
_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user