Skip to content

[9.20] chg: usr: dnssec-ksr now supports KSK rollovers

The tool 'dnssec-ksr' now allows for KSK generation, as well as planned KSK rollovers. When signing a bundle from a Key Signing Request (KSR), only the key that is active in that time frame is being used for signing. Also, the CDS and CDNSKEY records are now added and removed at the correct time.

Closes #4697 (closed)

Closes #4705 (closed)

Backport of MR !9452 (merged)

Merge request reports