Checklist: Review and Manage a Signed Zone

 

Applies To: Windows Server 2012 R2, Windows Server 2012

Checklist: Deploy DNSSEC > Checklist: Sign a Zone > Checklist: Distribute Trust Anchors > Checklist: Deploy DNSSEC Policies to DNS Clients > Checklist: Review and Manage a Signed Zone

This parent checklist includes links to subordinate checklists that help you complete the required tasks.

Before you complete the tasks in this checklist, make sure that you have performed the prerequisite tasks in the parent checklist, such as reviewing conceptual information about DNSSEC and signing at least one DNS zone.

Most of the tasks in this checklist are optional. Depending on your environment, you might have to perform some or all of these procedures.

Note

Complete the tasks in this checklist in order. When a reference link takes you to a conceptual topic or to a subordinate checklist, return to this topic after you review the conceptual topic or after you complete the tasks in the subordinate checklist so that you can proceed with the remaining tasks in this checklist.

  Checklist: Review and Manage a Signed Zone

Task

Reference

Review DNSSEC concepts for managing a signed zone.

DNSSEC in Windows

Review the status of your signed zone.

Procedure: Review DNSSEC Parameters and Settings

(Optional) Modify zone signing parameters.

Checklist: Reconfigure Zone Signing Parameters on a Signed Zone

(Optional) Perform a manual key rollover.

Checklist: Perform a Manual Key Rollover

(Optional) Revoke signing keys.

Checklist: Perform an Emergency Key Revocation

(Optional) Move the Key Master role to another DNS server.

Checklist: Move the Key Master Role

(Optional) Unsign a zone.

Checklist: Revert to an Unsigned Zone

(Optional) Perform debug log rollover.

Procedure: Enable DNS Diagnostic Events

See also

Overview of DNSSEC

DNSSEC in Windows

DNSSEC Deployment Planning

Appendix A: DNSSEC Terminology

Appendix B: Windows PowerShell for DNS Server