Glossary
DNSSEC
DS record
A digest of a child zone’s key-signing key, published in the parent zone. It is the single link between a zone’s signatures and the chain of trust, and updating it is the step that most often gets missed at a key rollover.
Defined in RFC 4034 §5.
Where this appears
The lessons that use this term, and what each is for.
Advanced Email TrustThe dependency that decides availabilityDetermine from DNS alone whether DANE is even possible for a given domain.Domain Security FundamentalsDNSKEY, RRSIG, DS and NSECIdentify each DNSSEC record type in a real answer and say what job it does.Domain Security FundamentalsWalking the chain of trustFollow a chain from the root to a zone and confirm each link yourself.Domain Security FundamentalsHow DNSSEC breaks in productionDiagnose a SERVFAIL caused by DNSSEC and name the specific failure.DNS Security PractitionerThe rollover that breaks delegationsPerform a KSK rollover in an order that never leaves the parent pointing at nothing.DNS Security PractitionerLetting the parent update itselfPublish CDS and CDNSKEY so a rollover needs no registrar interaction.Domain Security PractitionerA broken chain you cannot fixDecide what to do about a DNSSEC failure in a zone somebody else operates.