dnssec: ds showing hidden 3+ days after key roll

Larry Rosenman ler at lerctr.org
Tue Feb 8 17:00:11 UTC 2022


Greetings,
     new poster.  I just converted over to DNSSEC-policy,  and rolled my 
KSK.  I see:
key: 269 (RSASHA256), KSK
   published:      yes - since Sun Feb  6 14:31:32 2022
   key signing:    yes - since Sun Feb  6 14:31:32 2022

   No rollover scheduled
   - goal:           omnipresent
   - dnskey:         omnipresent
   - ds:             hidden
   - key rrsig:      omnipresent


ler in thebighonker in namedb🔒 on  master [!] as 🧙
❯

Is it normal to see the ds as hidden?  It IS published, and I told rndc 
that.

Any insight appreciated.

-- 
Larry Rosenman                     http://www.lerctr.org/~ler
Phone: +1 214-642-9640                 E-Mail: ler at lerctr.org
US Mail: 5708 Sabbia Dr, Round Rock, TX 78665-2106


More information about the bind-users mailing list