Re: Automating a KSK rollover

2009-07-06 Thread Stephane Bortzmeyer
On Sat, Jul 04, 2009 at 10:36:40PM -0700, Shane W shane-b...@csy.ca wrote a message of 18 lines which said: Is there some sort of standardized way as yet to communicate key changes to an upstream zone or in this case a lookaside provider? There is a standard registrar2registry interface, an

Re: Automating a KSK rollover

2009-07-05 Thread Mark Elkins
I've added some automation around signing zones. For the KSK - it has a default life of 12 month. I'm looking at having two valid KSK's running with an overlap of 6 month. This means updating dlv.isc.org every 6 months, adding a new key, removing the old key and leaving the key thats 6 months old.