On 9 Dec 2025, at 12:38, Libor Peltan
<libor.peltan(a)nic.cz> wrote:
I think this is an error in Knot DNS's design. Maybe we should modify the behavior so
that the knotc zone-ksk-submitted command has an (optional) additional parameter where the
user could specify the parent DS's TTL, and also adds the (possibly) configured
parent-delay.
What do you think?
I agree that zone-ksk-submitted should behave more like the automated ksk submission
mechanism, so with additional parameters for parent ds ttl etc.
It’s not a big problem to wait before running zone-ksk-submitted, but it was unclear
from the docs for me whether knot would delay or remove the key immediately.
On 9 Dec 2025, at 12:38, Anand Buddhdev
<anandb(a)ripe.net> wrote:
You can configure a "submission" section in knot.conf, and provide trusted
resolvers there. Then Knot DNS will watch for DS record updates at the parent, and
consider the TTL before starting the DNSKEY retire process.
I will probably test that on our subdomains and in the future for .is.
The good news is that we’re almost done doing an algorithm rollover for .is.
The new DS record was published last night and we’ll trigger knot to finish
the rollover tomorrow. I’ve been very impressed with how well knot handled
the rollovers :)
.einar