This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/dns-wg@ripe.net/
[dns-wg] RIPE NCC DNS operations update
- Previous message (by thread): [dns-wg] RIPE NCC DNS operations update
- Next message (by thread): [dns-wg] RIPE NCC DNS operations update
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Jim Reid
jim at rfc1035.com
Wed May 11 14:07:19 CEST 2022
> On 11 May 2022, at 12:53, Anand Buddhdev <anandb at ripe.net> wrote: > > On Tuesday 3 May, we performed a DNSSEC Key Signing Key (KSK) roll-over for all the zones that we maintain and sign. During this roll-over, we dropped the Zone Signing Keys (ZSKs), and began signing the zones with just their new KSKs. Technically, these keys are the same as any other KSKs, but since they sign the entire zone, and there's no ZSK, such KSKs are informally known as Combined Signing Keys (CSKs). Many thanks for the update Anand. Could you give a bit more detail on why you decided to dump the ZSKs? Was it just a matter of having fewer keys to manage and fewer moving parts that could break?
- Previous message (by thread): [dns-wg] RIPE NCC DNS operations update
- Next message (by thread): [dns-wg] RIPE NCC DNS operations update
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[ dns-wg Archives ]