Checklist: Perform an Emergency Key Revocation

 

Applies To: Windows Server 2012 R2, Windows Server 2012

Checklist: Deploy DNSSEC > Checklist: Sign a Zone > Checklist: Distribute Trust Anchors > Checklist: Deploy DNSSEC Policies to DNS Clients > Checklist: Perform an Emergency Key Revocation

This parent checklist includes links to procedures that help you complete the required tasks.

Before you complete the tasks in this checklist, make sure you that have performed the prerequisite tasks in the parent checklist.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a conceptual topic or to a subordinate checklist, return to this topic after you review the conceptual topic or after you complete the tasks in the subordinate checklist so that you can proceed with the remaining tasks in this checklist.

  Checklist: Perform an Emergency Key Revocation

Task

Reference

Review conceptual information about DNSSEC signing keys and key rollover.

Signing keys

Trust Anchors

Replace signing keys and re-sign the zone.

Procedure: Replace Signing Keys

Distribute trust anchors.

Procedure: Import a Trust Point

See also

Overview of DNSSEC

DNSSEC in Windows

DNSSEC Deployment Planning

Appendix A: DNSSEC Terminology

Appendix B: Windows PowerShell for DNS Server