On Oct 7, 2014, at 1:59 PM, Wessels, Duane <dwessels@verisign.com> wrote:
If my reading of the draft is correct, the Double-KSK method most accurately describes what the root zone management partners had been talking about during our 2013 discussions.
Are there minutes/notes from those discussions? And: yay for that choice. The draft lists the tradeoff as: In essence, Double-KSK means that the new KSK is introduced first and used to sign the DNSKEY RRset. The DS record is changed, and finally the old KSK removed. It limits interactions with the parent to a minimum but, for the duration of the rollover, the size of the DNSKEY RRset is increased. ...which seems right when the "parent" is "many resolvers using different methods of pulling the root key". --Paul Hoffman