You need to enable JavaScript to use the communication tool powered by OpenWidget

What Is Key Rollover?

Key Rollover — the coordinated replacement of a DNSSEC signing key while old and new DNSKEY, signature, and sometimes DS data overlap long enough to preserve validation.

DNSSEC authenticates DNS data and protects its integrity with digital signatures; it does not encrypt queries. The chain of trust runs from the root through a DS record to the child zone’s keys, and an inconsistent link causes validation failure.

New from NIC.UA: a powerful AI website builder

Popular Questions About Key Rollover

  • What does Key Rollover mean?

    Key Rollover — the coordinated replacement of a DNSSEC signing key while old and new DNSKEY, signature, and sometimes DS data overlap long enough to preserve validation.

  • How does this element participate in DNSSEC?

    It creates, publishes, or validates part of the chain of trust so a validating resolver can determine whether data was signed by an authorized key and remained unchanged.

  • What should be checked during configuration?

    Verify algorithms, signature validity periods, DS-to-DNSKEY matching, required records on every authoritative server, and successful external validation before removing old keys.

  • Helpful articles

    • Glossary

      • Latest news & promotions

          Loading…