[ksk-rollover] (Un)planning future KSK replacements

Ray Bellis ray at isc.org
Fri Mar 29 11:38:01 UTC 2019



On 29/03/2019 12:28, Salz, Rich via ksk-rollover wrote:

> What is the purpose of doing a key rollover?  I'll claim that it is
> to help make sure you're ready to handle an unplanned situation. If
> nothing goes wrong, then you don't need to change the key. If
> something does go wrong you do need to react; the speed required
> depends on the circumstances.

Indeed - if you need to do it because the current key has been
compromised then 5011 doesn't help at all because of the 30 day 
hold-time timer.

Ray





More information about the ksk-rollover mailing list