[dns-operations] Few questions regarding DNSSEC
miek at miek.nl
Thu Oct 31 17:15:18 UTC 2013
[ Quoting <andreev.peter at gmail.com> in "Re: [dns-operations] Few questions ..." ]
> 1) It's up to you, if your zones are small and keys are long, you can live
> without rotation longer. For example we rotate KSK every year and ZSK every
> 3 months with SHA256 and 10M records in zone. Also take a look at
Or don't roll your keys at all (except in a emergency).
For my personal zones I use pretty much static keys.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 198 bytes
Desc: Digital signature
More information about the dns-operations