I have read through RFC 4641 and I believe I understand the various key
roll over procedures, but the RFC does not mention the scenario of
adding the DS records to the parent before publishing and/or using the
new KSKs.  It is safe to pre-publish new DS records and once it has
propagated to slave servers + it's original TTL, swap out the KSK and
resign the DNSKEY RRset?
-- 
Loren M. Lang
[email protected]
http://www.north-winds.org/


Public Key: ftp://ftp.north-winds.org/pub/lorenl_pubkey.asc
Fingerprint: 10A0 7AE2 DAF5 4780 888A  3FA4 DCEE BB39 7654 DE5B

Attachment: signature.asc
Description: Digital signature

_______________________________________________
bind-users mailing list
[email protected]
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to