On 13 jun 2014, at 13:52, Petr Spacek <[email protected]> wrote:

> I would expect that <KSK /> flag appears only after ds-seen command, i.e. 
> when the key reaches ACTIVE state.
> 
> It is intentional or is it a bug?

The KSK key rollover works by signing the DNSKEY RRset with all ready/active 
keys (aka double sign), so this is intentional.


        jakob

_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to