[DNSOP] Re: I-D Action: draft-ietf-dnsop-dnssec-keyrestore -01.txt

Peter Thomassen <[email protected]> Mon, 20 Jul 2026 21:30:46 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
Hi Martin,

On 5/18/26 11:46, Martin Pels wrote:
>> 1. While performing this procedure to recover from an unusable ZSK or CSK the SOA record of the zone cannot be changed. This is because at the moment the new DNSKEY gets introduced into the zone, the DNSKEY RRset cannot be signed with the old, unusable key.
> 
> Correction, this should read:
> 
> "While performing this procedure to recover from an unusable ZSK or CSK the SOA record of the zone cannot be changed. This is because at the moment the new DNSKEY gets introduced into the zone, the _SOA_ RRset cannot be signed with the old, unusable key."

I guess that depends on whether the replication mechanism used for the zone relies on SOA record changes at all.

Best,
Peter

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]