8-9 March 2018
Centro de Convenciones de Puerto Rico
America/Puerto_Rico timezone

The Curious Case of the Crippling DS record

8 Mar 2018, 15:00
209-BC (Centro de Convenciones de Puerto Rico)


Centro de Convenciones de Puerto Rico

100 Calle Guamaní San Juan 00907 Puerto Rico
Roy Arends (ICANN)


When a DNSSEC Key Signing Key (KSK) is rolled, the Delegation Signer (DS) records in the parent are updated as well. A DS record contains the "Digest Type" used to produce the digest over the KSK. Care must be taken when "rolling" the digest type during a KSK roll. It may well cause the entire zone to become bogus. My presentation will show how a Top Level Domain went unreachable due to an obscure requirement in the standard and will show inconsistencies between validator implementations.
Talk Duration 30 Minutes

Primary author

Roy Arends (ICANN)

Presentation Materials

