and the user shall propagate them to the parent. The server periodically checks for
DS at the parent zone and when positive, finishes the rollover.
-To share KSKs among zones, set the ksk-shared policy parameter. It is strongly discouraged to
-change the policy ``id`` afterwards! The shared key's creation timestamp will be equal for all
-zones, but other timers (e.g. activate, retire) may get out of sync. ::
+To share KSKs among zones, set the :ref:`policy_ksk-shared` policy parameter. Please note
+that changing the policy ``id`` afterwards can have unexpected conseqences!
+The shared key's creation timestamp will be equal for all zones, but other timers
+(e.g. activate, retire) may get out of sync. ::
policy:
- id: shared
\fIDefault:\fP see default for \fI\%ksk\-size\fP
.SS ksk\-shared
.sp
-If enabled, all zones with this policy assigned will share one KSK.
+If enabled, all zones with this policy assigned will share one or more KSKs.
+More KSKs can be shared during a KSK rollover.
.sp
\fBWARNING:\fP
.INDENT 0.0
.INDENT 3.5
-It is discouraged to modify policy \fI\%id\fP when shared KSK is enabled.
+As the shared KSK set is bound to the policy \fI\%id\fP, renaming the
+policy breaks this connection and new shared KSK set is initiated when
+a new KSK is needed.
.UNINDENT
.UNINDENT
.sp
But when a KSK rollover takes place, they will use the same new key afterwards.
.. WARNING::
- It is discouraged to modify policy :ref:`id<policy_id>` when :ref:`shared KSK<policy_ksk-shared>`
- is enabled.
+ Changing the policy :ref:`id<policy_id>` must be done carefully if shared
+ KSK is in use.
.. _DNSSEC Delete algorithm:
ksk-shared
----------
-If enabled, all zones with this policy assigned will share one KSK.
+If enabled, all zones with this policy assigned will share one or more KSKs.
+More KSKs can be shared during a KSK rollover.
.. WARNING::
- It is discouraged to modify policy :ref:`id<policy_id>` when shared KSK is enabled.
+ As the shared KSK set is bound to the policy :ref:`id<policy_id>`, renaming the
+ policy breaks this connection and new shared KSK set is initiated when
+ a new KSK is needed.
*Default:* off