![Radware Alteon Скачать руководство пользователя страница 748](http://html.mh-extra.com/html/radware/alteon/alteon_application-manual_781134748.webp)
Alteon Application Switch Operating System Application Guide
Global Server Load Balancing
748
Document
ID:
RDWR-ALOS-V2900_AG1302
As a result, the following occurs:
1. A new KSK is created and stored in the key storage location.
2. All the relevant keys are signed with the new KSK.
3. The new KSK is published using DNSKEY.
4. The system administrator is notified through SNMP, console, or e-mail that a new KSK has been
created.
5. The KSK rollover is counted to zero.
6. The resource record of the parent points to the new DNSKEY.
7. A timeout of 48 hours, in addition to the TTL of the original KSK, starts.
8. The old DNSKEY is removed.
9. The system administrator is notified through SNMP, console, or e-mail that a new KSK is created
and in place.
Emergency Rollovers
Emergency rollover is an administrator action.
When an emergency KSK rollover is enabled, Alteon waits for the DS record to be signed by the
parent. The timer waits a pre-defined period (KSK Rollover Phase timer). If the administrator does
not ensure that the DS was signed, a warning is issued that the DNSSEC service might be disturbed.
To initiate a ZSK emergency rollover
1. Initiate the emergency rollover.
The system administrator is warned through SNMP, console, or e-mail that an emergency ZSK
rollover has been initiated, which can disrupt services.
2. The system administrator must confirm the emergency rollover.
The system administrator is notified through SNMP, console, or e-mail that a new ZSK has been
created.
3. A new ZSK is created and stored in the key storage location.
4. The new ZSK is signed with the existing ZSK.
5. The new ZSK is published using DNSKEY.
6. All zone records are signed with the new ZSK, including all RRSIGs still existing in cache.
7. The old RRSIGs are removed from storage.
8. The old ZSK are revoked and removed from storage.
9. The system administrator is notified through SNMP, console, or e-mail that the emergency
rollover is complete.
To initiate a KSK emergency rollover
Initiate the emergency rollover. As a result, the following occurs:
1. A new KSK is created and stored in the key storage location.
2. All the relevant keys are signed with the new KSK.
3. The new KSK is published using DNSKEY.
Содержание Alteon
Страница 2: ...Alteon Application Switch Operating System Application Guide 2 Document ID RDWR ALOS V2900_AG1302 ...
Страница 42: ...Alteon Application Switch Operating System Application Guide Preface 42 Document ID RDWR ALOS V2900_AG1302 ...
Страница 582: ...Alteon Application Switch Operating System Application Guide High Availability 582 Document ID RDWR ALOS V2900_AG1302 ...