1. Generate key file for new ZSK.
|
›_ Console |
|---|
|
Key file for new ZSK
If you want to generate key files for ECC keys, follow steps in section For ECC Keys.
-
Add the new ZSK to the zone file
example.net.
|
example.net |
|---|
|
-
Re-sign the zone with the KSK and old ZSK.
|
›_ Console |
|---|
|
Signing zone with old ZSK
-
Wait for the zone transfer time and TTL of the key set.
-
Sign the zone with new ZSK.
|
›_ Console |
|---|
|
Signing zone with new ZSK
-
Wait for the zone transfer time and maximum TTL used in the zone.
-
Remove old ZSK from the zone file example.net
|
example.net |
|---|
|
-
Re-sign the zone with the KSK. Now we have only one ZSK in
example.netso it will automatically pick this new ZSK for signing zone.
|
›_ Console |
|---|
|
Signing zone with new ZSK
-
Stop and start the named service using below command.
|
›_ Console |
|---|
|
Starting named service
This completes the Integration for Bind9 with Utimaco CryptoServer HSM.