2 DNS Key Status Types and Filenames
5 cfB | cfB s | cfB s | cfB | cfB
6 cfB | cfB | cfB | cfB | cfB | cfB | cfB
7 l | l | n | l | l | c | lfCW .
8 Status Key Filename used for dnssec-zkt
9 \^ Type Flags public private signing? label
11 active ZSK 256 .key .private y act ive
12 KSK 257 .key .private y act ive
14 published ZSK 256 .key .published n pub lished
15 KSK 257 .key .private n sta ndby
17 depreciated (retired) ZSK 256 .key .depreciated n dep reciated
19 revoked KSK 385 .key .private y rev oked
21 removed KSK 257 k*.key k*.private n -
23 sep KSK 257 .key - n sep
26 (master KSK 257 M...key .private n -)
34 Zone signing key rollover (pre-publish RFC4641)
37 rfB cfB |cfB |cfB |cfB
38 lfB |cfB |cfB |cfB |cfB
40 action create change remove
41 keys newkey sig key old key
43 zsk1 active active depreciated
44 zsk2 published active active
46 RRSIG zsk1 zsk1 zsk2 zsk2
50 Key signing key rollover (double signature RFC4641)
53 rfB cfB |cfB |cfB |cfB
54 lfB |cfB |cfB |cfB |cfB
56 action create change remove
57 keys newkey delegation old key
59 ksk\d1\u active active active
60 ksk\d2\u active active active
62 DNSKEY RRSIG ksk1 ksk1,ksk2 ksk1,ksk2 ksk2
64 DS at parent DS\d1\u DS\d1\u DS\d2\u DS\d2\u
66 .\"RRSIG DNSKEY\dksk1\u DNSKEY\dksk1,ksk2\u DNSKEY\dksk1,ksk2\u DNSKEY\dksk2\u
69 Key signing key rollover (rfc5011)
75 action newkey change delegation
76 keys & rollover & remove old key
78 ksk\d1\u active revoke\v'-0.2'\(dg\v'+0.2'
79 ksk\d2\u standby active active
80 ksk\d3\u standby\v'-0.2'\(dd\v'+0.2' standby
82 DNSKEY RRSIG ksk1 ksk1,ksk2 ksk2
84 Parent DS DS\d1\u DS\d1\u DS\d2\u
85 DS\d2\u DS\d2\u DS\d3\u
89 Have to remain until the remove hold-down time is expired,
90 which is 30days at a minimum.
93 Will be the standby key after the hold-down time is expired
95 Add holdtime \(eq max(30days, TTL of DNSKEY)