Describe ZSK+KSK here.

RFC 4035

2.1. Including DNSKEY RRs in a Zone

To sign a zone, the zone's administrator generates one or more
   public/private key pairs and uses the private key(s) to sign
   authoritative RRsets in the zone.

MoinQ: DNS/DNSSEC/DNSKEY/ZSK+KSK (last edited 2023-06-25 13:01:39 by ToshinoriMaeno)