Checklist: Manage Signing Keys

 

Applies To: Windows Server 2012 R2, Windows Server 2012

Checklist: Deploy DNSSEC > Checklist: Sign a Zone > Checklist: Distribute Trust Anchors > Checklist: Deploy DNSSEC Policies to DNS Clients > Checklist: Manage Signing Keys

This parent checklist includes links to procedures that help you complete the required tasks.

Before you complete the tasks in this checklist, make sure that you have performed the prerequisite tasks in the parent checklist.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a conceptual topic or to a subordinate checklist, return to this topic after you review the conceptual topic or after you complete the tasks in the subordinate checklist so that you can proceed with the remaining tasks in this checklist.

  Checklist: Manage Signing Keys

Task

Reference

Review important concepts about choosing and managing DNSSEC signing keys.

DNS Zones

Cryptographic algorithms

Trust Anchors

(Optional) Perform a manual key rollover and revocation.

Checklist: Perform an Emergency Key Revocation

(Optional) Perform a manual key rollover without revocation.

Checklist: Perform a Manual Key Rollover

Review the status of signing keys.

Procedure: Review Signing Keys

Retire a signing key on the next key rollover.

Procedure: Retire a Signing Key

See also

Overview of DNSSEC

DNSSEC in Windows

DNSSEC Deployment Planning

Appendix A: DNSSEC Terminology

Appendix B: Windows PowerShell for DNS Server