Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

A DS RR contains a hash of a child zone's KSK and can be used as a trust anchor in some security-aware resolvers and to create a secure delegation point for a signed subzone in DNS servers. As illustrated in Figure 22.1, the DS RR in the parent zone corpxyz.com contains a hash of the KSK of the child zone sales.corpxyz.com, which in turn has a DS record that contains a hash of the KSK of its child zone, nw.sales.corpxyz.com.

Anchor
bookmark2030
bookmark2030
Figure 22.1 Place for Fig. 22.


Drawio
bordertrue
viewerToolbartrue
fitWindowfalse
diagramName22.1
simpleViewerfalse
width
revision1


Drawio
bordertrue
viewerToolbartrue
fitWindowfalse
diagramNameArrows1
simpleViewerfalse
width
revision1

...