Alteon Application Switch Operating System Application Guide
Global Server Load Balancing
746
Document
ID:
RDWR-ALOS-V2900_AG1302
DNSSEC Key Rollover
DNSSEC key maintenance requires administrative logic and deals with issues such as key
revocation, key expiration, and key compromise. RFC 4641 (DNSSEC Operational Practices) advises
how to manage keys and what are the recommended maintenance procedures.
A rollover is an automated process during which new DNSSEC keys are created, existing records are
resigned, old DNSSEC keys are revoked, and new keys are published to the public using the
Internet. An automated rollover is initiated periodically by the system administrator. An emergency
rollover is initiated as necessary.
Contrary to other cipher key mechanisms that are revoked and created, DNSSEC rollover is an
essential part of the RFC definition to ensure the continuous service for global Internet service.
This section includes the following sub-sections:
•
Preventing Expiration of KSK or ZSK in Rollover Situations, page 746
•
Automated ZSK Rollover, page 746
•
Automated KSK Rollover, page 747
•
•
Automatic NSEC and NSEC3 Record Creation, page 752
Preventing Expiration of KSK or ZSK in Rollover Situations
Alteon includes a DNS key rollover mechanism for preventing expiration. The following information
is relevant when the ZSK and the KSK are assigned to the same zone. The goal of an automatic
rollover process is that the created key is published and RRs are signed before the old key is
revoked.
•
During key rollovers (automatic, emergency, KSK or ZSK), the KSK must finalize before the ZSK
rollover begins.
•
To prevent overload on the CPU when creating keys, limit the number of bulk keys to be created
to 10 at a time. If more keys are needed, their creation is queued.
•
During an emergency rollover, the emergency rollover takes precedence over any other type of
rollover. For example, when the administrator has four ZSKs in queue for automatic rollover and
activates a ZSK emergency for another ZSK, the emergency ZSK is executed directly. Existing
rollovers of the same key are cancelled and a console or syslog message is generated.
Automated ZSK Rollover
Alteon includes the following automated ZSK rollover methods:
•
Zone Signing Key—As specified in RFC 4641, section 4.2.1.1. Pre-Publish Key Rollover
•
Key Signing Key—As specified in RFC 4641, section 4.2.2
The automatic rollover of the DNSSEC keys is performed according to the parameters specified in
Table 63:
Table 63: Automated ZSK Rollover as Defined in RFC 4641
Initial DNSKEY
New DNSKEY
New RRSIGs
DNSKEY Removal
SOA0
SOA1
SOA2
SOA3
RRRSIG10(SOA0)
RRRSIG10(SOA1)
RRRSIG10(SOA2)
RRRSIG10(SOA3)
DNSKEY1
DNSKEY1
DNSKEY1
DNSKEY1
DNSKEY10
DNSKEY10
DNSKEY10
DNSKEY10
DNSKEY11
DNSKEY11