For KSKs the DS lifecycle at the parent stays visible under
role=KSK; switching to role=ZSK additionally
drops dns_ds_*, dns_cds_*, and
dns_cdnskey_* events since ZSKs have no parent presence.
KSK · tag 57017
Algorithm: 14
Key id: Kdnslab.us.+014+57017
First seen: 2026-04-11T11:03:18Z
K*.key file timings
Field
Value
Created
2024-10-22 22:11:30 UTC
Publish
2024-10-22 22:11:30 UTC
Activate
2024-10-22 22:11:30 UTC
Revoke
—
Inactive
2025-10-22 22:11:30 UTC
Delete
2025-10-24 00:11:30 UTC
SyncPublish
2024-10-23 23:16:30 UTC
SyncDelete
—
K*.state file — state machine
Field
Value
GoalState
hidden
DNSKEYState
hidden
KRRSIGState
hidden
DSState
unretentive
K*.state file — timestamps
Field
Value
Generated
20241022221130 (Tue Oct 22 22:11:30 2024)
Published
20241022221130 (Tue Oct 22 22:11:30 2024)
Active
20241022221130 (Tue Oct 22 22:11:30 2024)
Retired
20251022221130 (Wed Oct 22 22:11:30 2025)
Removed
20251024001130 (Fri Oct 24 00:11:30 2025)
DNSKEYChange
20251030133400 (Thu Oct 30 13:34:00 2025)
KRRSIGChange
20251030133400 (Thu Oct 30 13:34:00 2025)
DSChange
20251022221130 (Wed Oct 22 22:11:30 2025)
PublishCDS
20241023231630 (Wed Oct 23 23:16:30 2024)
Rollover view
This key's lifecycle on a time axis with phase colouring. For KSKs
the DS-at-parent overlay stripe shows when the parent-side chain of
trust was actually complete, independently of BIND's internal state
machine.
Live DNS observations and rndc dnssec -status
reports for this key. For KSKs this includes the DS lifecycle at
the parent zone (captured by key tag from the DS rdata).
File event timeline
On-disk changes to this key's K*.state / K*.key files.