Use DS records as trust anchors, not DNSKEYs.
This allows us to query for the root zone DNSKEY RRset and validate it, thus automatically handling KSK rollover.
Showing
Please register or sign in to comment
This allows us to query for the root zone DNSKEY RRset and validate it, thus automatically handling KSK rollover.