[Opendnssec-develop] KSK Rollovers

Jakob Schlyter jakob at kirei.se
Sun Jul 12 09:51:10 UTC 2009


my idea is that we at some point write a program that given a zonelist  
compares the DNSKEYs at the child with the DS at each zone's parent,  
and report back. or it could take action to make sure they are in sync  
(using the appropriate child to registrar protocol).

IMHO, writing such a program (reporting only) should be doable i about  
3 points and I think we should consider writing one before 1.0.

	jakob




More information about the Opendnssec-develop mailing list