-
Generate a key file for the new KSK.
|
›_ Console |
|---|
|
Key file for new KSK
-
Add the new KSK to the zone file example.net.
|
example.net |
|---|
|
-
Sign the zone with the old and new KSK.
|
›_ Console |
|---|
|
Signing zone with old and new KSK
-
Wait for the zone transfer time, TTL of DNSKEY resource record set and TTL on the DS record set.
-
Remove the old KSK entry from zone file example.net.
|
example.net |
|---|
|
-
Sign the zone with the new KSK.
|
›_ Console |
|---|
|
Signing the zone with new KSK