First-ever DNSSEC root key rollover
redhat.com
First-ever DNSSEC root key rollover
1–10 of 75 posts
Re: First-ever DNSSEC root key rollover
#2Re: First-ever DNSSEC root key rollover
#3I have a DNSSEC signed zone, do I need to do anything? Like generate a new key using this new root key?
Re: First-ever DNSSEC root key rollover
#4I have a DNSSEC signed zone, do I need to do anything? Like generate a new key using this new root key?
Re: First-ever DNSSEC root key rollover
#5I have a DNSSEC signed zone, do I need to do anything? Like generate a new key using this new root key?
Re: First-ever DNSSEC root key rollover
#6https://dnssec-name-and-shame.com
To check DANE (such as freebsd.org port 443):
Re: First-ever DNSSEC root key rollover
#7To check DNSSEC: https://dnssec-name-and-shame.com To check DANE (such as freebsd.org port 443): https://www.huque.com/bin/danecheck
Re: First-ever DNSSEC root key rollover
#8I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?
Re: First-ever DNSSEC root key rollover
#9What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did. I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?
Re: First-ever DNSSEC root key rollover
#10What is the purpose of rolling over the key, if the new key is simply signed by the old one? Meaning it has exactly as much security as the old key did. I can understand it if the new key was a different algorithm, or key-length or something. But what is the purpose in simply picking a new key?