Speaker
Roy Arends
(ICANN)
Description
When a DNSSEC Key Signing Key (KSK) is rolled, the Delegation Signer (DS) records in the parent are updated as well. A DS record contains the "Digest Type" used to produce the digest over the KSK. Care must be taken when "rolling" the digest type during a KSK roll. It may well cause the entire zone to become bogus.
My presentation will show how a Top Level Domain went unreachable due to an obscure requirement in the standard and will show inconsistencies between validator implementations.
Talk Duration | 30 Minutes |
---|
Primary author
Roy Arends
(ICANN)