For KSKs the DS lifecycle at the parent stays visible under
role=KSK; switching to role=ZSK additionally
drops dns_ds_*, dns_cds_*, and
dns_cdnskey_* events since ZSKs have no parent presence.
ZSK · tag 9412
Algorithm: 14
Key id: Kfus3dprinting.org.+014+09412
First seen: 2026-05-17T00:50:07Z
K*.key file timings
Field
Value
Created
2026-05-17 00:50:07 UTC
Publish
2026-05-17 00:50:07 UTC
Activate
2026-05-17 02:05:07 UTC
Revoke
—
Inactive
2026-07-16 02:05:07 UTC
Delete
2026-07-26 03:10:07 UTC
SyncPublish
—
SyncDelete
—
K*.state file — state machine
Field
Value
GoalState
omnipresent
DNSKEYState
rumoured
ZRRSIGState
rumoured
K*.state file — timestamps
Field
Value
Generated
20260517005007 (Sun May 17 00:50:07 2026)
Published
20260517005007 (Sun May 17 00:50:07 2026)
Active
20260517020507 (Sun May 17 02:05:07 2026)
Retired
20260716020507 (Thu Jul 16 02:05:07 2026)
Removed
20260726031007 (Sun Jul 26 03:10:07 2026)
DNSKEYChange
20260517005007 (Sun May 17 00:50:07 2026)
ZRRSIGChange
20260517005007 (Sun May 17 00:50:07 2026)
Rollover view
This key's lifecycle on a time axis with phase colouring. For KSKs
the DS-at-parent overlay stripe shows when the parent-side chain of
trust was actually complete, independently of BIND's internal state
machine.
Live DNS observations and rndc dnssec -status
reports for this key. For KSKs this includes the DS lifecycle at
the parent zone (captured by key tag from the DS rdata).
File event timeline
On-disk changes to this key's K*.state / K*.key files.