Chapter 15. Parent Action During Child KSK Compromise

Table of Contents

Ensure that the KSK Compromise Notification Came Over a Secure Channel
Delete the Child's Keyset File at the Parent
Re-sign the Parent Zone
Reload the Zone

During a KSK compromise the secure status of the child zone is dropped. This is done by deleting the DS record in the parent zone.