[ksk-change] Which style of rollover were people thinking of?

Paul Hoffman paul.hoffman at vpnc.org
Tue Oct 7 23:14:50 UTC 2014


On Oct 7, 2014, at 1:59 PM, Wessels, Duane <dwessels at verisign.com> wrote:

> If my reading of the draft is correct, the Double-KSK method most accurately
> describes what the root zone management partners had been talking about
> during our 2013 discussions.

Are there minutes/notes from those discussions?

And: yay for that choice. The draft lists the tradeoff as:
   In essence, Double-KSK means that the new KSK is introduced first and
   used to sign the DNSKEY RRset.  The DS record is changed, and finally
   the old KSK removed.  It limits interactions with the parent to a
   minimum but, for the duration of the rollover, the size of the DNSKEY
   RRset is increased.
...which seems right when the "parent" is "many resolvers using different methods of pulling the root key".

--Paul Hoffman


More information about the ksk-rollover mailing list