Update ZSK rotation instructions
This commit is contained in:
parent
0ffa5a95e4
commit
4155ad9324
1 changed files with 3 additions and 2 deletions
|
@ -15,9 +15,10 @@ Assumes:
|
|||
3. Sign DNSKEY RRs with KSK
|
||||
4. Sign rest of the zone with ZSK_c
|
||||
5. Publish signed zones, which includes:
|
||||
- DNSKEY RRs for ZSK_c and ZSK_n signed by KSK
|
||||
- DNSKEY RRs for ZSK_p, ZSK_c and ZSK_n signed by KSK
|
||||
- Every other RR signed by ZSK_c
|
||||
- Does not include ZSK_p DNSKEY RR nor any RRSIG signed by ZSK_p
|
||||
- Does not include any RRSIG signed by ZSK_p
|
||||
6. After cache expires, delete ZSK_p DNSKEY RR.
|
||||
|
||||
NSEC3PARAM
|
||||
----------
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue