Path: csiph.com!news.uzoreto.com!news.etla.org!nntp-feed.chiark.greenend.org.uk!ewrotcd!usenet-its.stanford.edu!usenet.stanford.edu!not-for-mail From: Tony Finch Newsgroups: comp.protocols.dns.bind Subject: Re: How to prepublish additional DNSKEY Date: Wed, 8 Jul 2020 16:32:29 +0100 Lines: 22 Approved: bind-users@lists.isc.org Message-ID: References: <3E18C1A0C550C44DA156DA5DA8ECCC6AB622808F@NICS-EXCH2.sbg.nic.at> NNTP-Posting-Host: lists.isc.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII X-Trace: usenet.stanford.edu 1594222359 32320 149.20.1.60 (8 Jul 2020 15:32:39 GMT) X-Complaints-To: action@cs.stanford.edu Cc: "bind-users@lists.isc.org" To: Klaus Darilion Return-Path: X-Original-To: bind-users@lists.isc.org Delivered-To: bind-users@lists.isc.org X-Cam-AntiVirus: no malware found X-Cam-ScannerInfo: http://help.uis.cam.ac.uk/email-scanner-virus In-Reply-To: <3E18C1A0C550C44DA156DA5DA8ECCC6AB622808F@NICS-EXCH2.sbg.nic.at> User-Agent: Alpine 2.20 (DEB 67 2015-01-07) X-Spam-Status: No, score=-1.3 required=5.0 tests=KAM_LAZY_DOMAIN_SECURITY, RCVD_IN_DNSWL_MED,RCVD_IN_MSPIKE_H4,RCVD_IN_MSPIKE_WL,SPF_HELO_PASS, SPF_NONE autolearn=disabled version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mx.pao1.isc.org X-BeenThere: bind-users@lists.isc.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: BIND Users Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-Mailman-Original-Message-ID: X-Mailman-Original-References: <3E18C1A0C550C44DA156DA5DA8ECCC6AB622808F@NICS-EXCH2.sbg.nic.at> Xref: csiph.com comp.protocols.dns.bind:15931 Klaus Darilion wrote: > > A signed zone shall be moved to another DNS provider. Hence I want to > add the public KSK of the gaining DNS provider as additional DNSKEY to > the zone. I guess you might already have seen this draft - it discusses long-term multi-provider setups rather than transitional ones, so it isn't direcly on point, but it still has some useful ideas. https://tools.ietf.org/html/draft-ietf-dnsop-multi-provider-dnssec > So, how is the correct process to add an additional DNSKEY (only the public key is known). I think you are looking for `dnssec-importkey`. Tony. -- f.anthony.n.finch http://dotat.at/ Viking, North Utsire, South Utsire, Northeast Forties: Northwesterly 4 to 6, becoming variable 2 to 4 except in South Utsire. Slight or moderate. Showers. Good.