* Daniel Stirnimann <daniel.stirnimann(a)switch.ch> [2018-10-24 10:28]:
  Hello Sebastian,
  http://dnsviz.net/d/6v6.de/W9AmtA/dnssec/
 Looking at the graph the new KSK (54879) is not signing anything right
 now. Shouldn't it sign the DNSKEY records of the ZSKs so that the
 chain stays intact when the DS record changed at the parent zone? 
 
 You are reading the graph wrong. The new KSK is signing the DNSKEY
 RRset. See:
 dig @ns1.karotte.org 6v6.de DNSKEY +dnssec 
Yeah, it was a brain fart together with the IMO suboptimal graph
display at dnsviz. Sorry for the noise.
Best Regards
Sebastian
--
GPG Key: 0x58A2D94A93A0B9CE (F4F6 B1A3 866B 26E9 450A  9D82 58A2 D94A 93A0 B9CE)
'Are you Death?' ... IT'S THE SCYTHE, ISN'T IT? PEOPLE ALWAYS NOTICE THE
SCYTHE.
            -- Terry Pratchett, The Fifth Elephant