On Thu, 9 Aug 2012, Jasper Wallace wrote: > > Hi, > > I have a domain but my registrar dosn't do dnssec so i use the isc dlv > system to publish my KSK. > > This all works ok. > > my current KSK is nearing the end of it's life so i want to do the ksk > rollover and get the new ksk in the isc dlv system. [snip] > I guess that i can go ahead and activate it, but I want to check that that > won't replace the existing key.
So i just decided to try it and it works, i now have 2 ksk's and the isc dlv system is happy with both. zkt-ls says 'act' for the new key. Would still like a definative answer to this tho :) > Presumably it's ok to have 2 KSK's for a short time? > > I'm using zkt-1.1.0 (compiled myself) on debian. > > -- [http://pointless.net/] [0x2ECA0975] ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ zkt-users mailing list zkt-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/zkt-users