[ksk-change] Which style of rollover were people thinking of?
Paul Hoffman
paul.hoffman at vpnc.org
Tue Oct 7 23:14:50 UTC 2014
On Oct 7, 2014, at 1:59 PM, Wessels, Duane <dwessels at verisign.com> wrote:
> If my reading of the draft is correct, the Double-KSK method most accurately
> describes what the root zone management partners had been talking about
> during our 2013 discussions.
Are there minutes/notes from those discussions?
And: yay for that choice. The draft lists the tradeoff as:
In essence, Double-KSK means that the new KSK is introduced first and
used to sign the DNSKEY RRset. The DS record is changed, and finally
the old KSK removed. It limits interactions with the parent to a
minimum but, for the duration of the rollover, the size of the DNSKEY
RRset is increased.
...which seems right when the "parent" is "many resolvers using different methods of pulling the root key".
--Paul Hoffman
More information about the ksk-rollover
mailing list