Forum Discussion

Anoop_Dharan_20's avatar
Anoop_Dharan_20
Icon for Nimbostratus rankNimbostratus
Jul 06, 2018

DNSSEC setup questions

Hello Folks,

 

We have two sites. Each site has two F5 DNS appliances that configured as cluster mode.

 

  1. If we configure DNSSEC in Site1 - DNS1 (active) appliance, how the DNSSEC KSK, ZSK and DS record sync with other 3 appliances. How long does it take?
  2. If Site1 - DNS1 (active) appliance failed down, any impact to the DNSSEC zone? Need re-gen the keys and re-sign the zone after RMA?
  3. If we change the "Rollover Time" and "Expiration Time" of the KSK and ZSK, any detail procedures to make it active and when to upload the new DS record to my parent zone? Follow old rollover period or new rollover period?
No RepliesBe the first to reply