Avoiding self-inflicted outages.
WHAT CAUSES MOST DNSSEC OUTAGES
Expired signatures Key rollover performed incorrectly The parent's delegation record not matching the current key Zone transfers between servers with inconsistent signing
WHY EXPIRY MATTERS
Signatures have a validity period, and an unsigned or expired zone fails validation entirely.
WHAT TO AUTOMATE
Re-signing, well before expiry.
WHAT KEY ROLLOVER REQUIRES
Publishing the new key Waiting for caches to learn it Switching signing Waiting again Removing the old key
WHY THE WAITING
Resolvers hold cached keys, and removing one too early breaks validation for them.
WHAT ROLLING THE KEY SIGNING KEY ADDITIONALLY REQUIRES
Updating the record at the parent, and waiting for that to propagate.
WHAT TO MONITOR
Signature expiry, with alerts well in advance Validation, from external validating resolvers Consistency between the parent record and your key
WHAT TO TEST
Validation from outside, using tools that report the chain.
WHAT TO PREFER IF YOU LACK THE OPERATIONAL CAPACITY
A provider offering managed signing.
WHY
Badly operated DNSSEC is worse than none.