[Opendnssec-develop] separate validity for signatures over DNSKEY

Matthijs Mekking matthijs at NLnetLabs.nl
Mon Mar 15 10:24:31 UTC 2010


Rickard Bellgrim wrote:
> Refresh KSK RRSIG when it is 15 days until it expires.
> Refresh ZSK RRSIG when it is 4 days until it expires.

What is a KSK RRSIG? What is a ZSK RRSIG?

I do know of a RRSIG record that covers the type DNSKEY...


Matthijs



More information about the Opendnssec-develop mailing list