Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

A DS RR contains a hash of a child zone's KSK and can be used as a trust anchor in some security-aware resolvers and to create a secure delegation point for a signed subzone in DNS servers. As illustrated in Figure 22.1, the DS RR in the parent zone corpxyz.com contains a hash of the KSK of the child zone sales.corpxyz.com, which in turn has a DS record that contains a hash of the KSK of its child zone, nw.sales.corpxyz.com.

Anchor
bookmark2030
bookmark2030
Figure 22.1 


Drawio
false
bordertrue1
viewerToolbartrue
fitWindowbaseUrlhttps://infoblox-docs.atlassian.net/wiki
diagramName22.1
zoom1
simpleViewerfalse
widthpageId22252211
custContentId7345821
lbox1
contentVer1
revision1


Drawio
bordertrue
viewerToolbartrue
fitWindowfalse
diagramNameArrows1
simpleViewerfalse
width1
baseUrlhttps://infoblox-docs.atlassian.net/wiki
diagramNameArrows1
zoom1
pageId22252211
custContentId7345815
lbox1
contentVer1
revision1


The first four fields specify the owner name, TTL, class and RR type. The succeeding fields are as follows:

...