Rolling Over a Key-Signing Key (KSK)

DNSSEC key-signing keys (KSKs) require annual rollover and key promotion.

KSK rollover begins annually when a replacement DNSSEC key version is automatically created. You need to complete the rollover process manually. You're notified that the new key version requires promotion in the Console. To avoid a service disruption, we also recommend that you set up alarms to ensure that you perform all required key rollovers on time. See DNSSEC for more information.

Was this article helpful?