Glossary
DNSSEC
RRSIG
The signature over an RRset, carrying the signing key’s identifier and an explicit validity window. Signatures expire on a wall-clock date, which is why a zone that stops being re-signed fails rather than degrades.
Defined in RFC 4034 §3.
Where this appears
The lessons that use this term, and what each is for.
Domain Security FundamentalsDNSKEY, RRSIG, DS and NSECIdentify each DNSSEC record type in a real answer and say what job it does.Domain Security FundamentalsHow DNSSEC breaks in productionDiagnose a SERVFAIL caused by DNSSEC and name the specific failure.DNS Security PractitionerSignatures expireExplain why a zone that was valid yesterday fails today with no change made to it.DNS Security PractitionerAnswering on the flyExplain how a signer denies a name without ever listing the ones that exist.DNS Security PractitionerRolling the signing keyChoose between pre-publish and double-signature, and say what each costs.Domain Trust ArchitectureWhat decays, and how fastGive each control a review cadence derived from how quickly it goes wrong.Domain Security PractitionerA broken chain you cannot fixDecide what to do about a DNSSEC failure in a zone somebody else operates.