为了玩具,我决定为我的KSK和ZSK做一个手动按键翻转. ZSK从退役过渡到死亡的时间是两周.考虑到大多数TTL小于48小时且传播延迟不超过24小时,这是一个大量的时间,似乎完全没必要.
我一直在阅读文件“Good Practices Guide for Deploying DNSSEC”,他们建议这两周延迟,但似乎没有给出延迟的理由.
是什么赋予了?
从论文:
The duration of the transition from one state to the next is a
function of the lifetime of the records in a zone,the time required
to deliver the zones to the external servers and clock jitter time
(Internet – Draft,DNSSEC Key Timing Considerations ) .
和
The recommended period during which a KSK is retired before it is
removed from the zone ( retirement time ) is four weeks. For the ZSK,
the recommended introduction time is four days and the retirement
time is two weeks.
解决方法
原文地址:https://www.jb51.cc/html/228333.html
版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。