For KSKs the DS lifecycle at the parent stays visible under
role=KSK; switching to role=ZSK additionally
drops dns_ds_*, dns_cds_*, and
dns_cdnskey_* events since ZSKs have no parent presence.
ZSK · tag 42278
Algorithm: 15
Key id: Ked25519.devries.tv.+015+42278
First seen: 2026-04-11T11:03:18Z
K*.key file timings
Field
Value
Created
2025-01-31 12:19:18 UTC
Publish
2025-01-31 12:19:18 UTC
Activate
2025-01-31 13:34:18 UTC
Revoke
—
Inactive
2025-03-02 13:34:18 UTC
Delete
2025-03-12 14:39:18 UTC
SyncPublish
—
SyncDelete
—
K*.state file — state machine
Field
Value
GoalState
hidden
DNSKEYState
hidden
ZRRSIGState
hidden
K*.state file — timestamps
Field
Value
Generated
20250131121918 (Fri Jan 31 12:19:18 2025)
Published
20250131121918 (Fri Jan 31 12:19:18 2025)
Active
20250131133418 (Fri Jan 31 13:34:18 2025)
Retired
20250302133418 (Sun Mar 2 13:34:18 2025)
Removed
20250312143918 (Wed Mar 12 14:39:18 2025)
DNSKEYChange
20250312133918 (Wed Mar 12 13:39:18 2025)
ZRRSIGChange
20250312143918 (Wed Mar 12 14:39:18 2025)
Rollover view
This key's lifecycle on a time axis with phase colouring. For KSKs
the DS-at-parent overlay stripe shows when the parent-side chain of
trust was actually complete, independently of BIND's internal state
machine.
Live DNS observations and rndc dnssec -status
reports for this key. For KSKs this includes the DS lifecycle at
the parent zone (captured by key tag from the DS rdata).
File event timeline
On-disk changes to this key's K*.state / K*.key files.