For KSKs the DS lifecycle at the parent stays visible under
role=KSK; switching to role=ZSK additionally
drops dns_ds_*, dns_cds_*, and
dns_cdnskey_* events since ZSKs have no parent presence.
KSK · tag 19841
Algorithm: 15
Key id: Kiodyn-dns.com.+015+19841
First seen: 2026-04-11T11:03:18Z
K*.key file timings
Field
Value
Created
2025-10-07 11:53:52 UTC
Publish
2025-10-07 11:53:52 UTC
Activate
2025-10-07 13:08:52 UTC
Revoke
—
Inactive
2026-01-05 13:08:52 UTC
Delete
2026-01-06 15:08:52 UTC
SyncPublish
2025-10-07 13:08:52 UTC
SyncDelete
—
K*.state file — state machine
Field
Value
GoalState
hidden
DNSKEYState
hidden
KRRSIGState
hidden
DSState
hidden
K*.state file — timestamps
Field
Value
Generated
20251007115352 (Tue Oct 7 11:53:52 2025)
Published
20251007115352 (Tue Oct 7 11:53:52 2025)
Active
20251007130852 (Tue Oct 7 13:08:52 2025)
Retired
20260105130852 (Mon Jan 5 13:08:52 2026)
Removed
20260106150852 (Tue Jan 6 15:08:52 2026)
DNSKEYChange
20260223090316 (Mon Feb 23 09:03:16 2026)
KRRSIGChange
20260223090316 (Mon Feb 23 09:03:16 2026)
DSChange
20260224110316 (Tue Feb 24 11:03:16 2026)
DSPublish
20251010105347 (Fri Oct 10 10:53:47 2025)
PublishCDS
20251007130852 (Tue Oct 7 13:08:52 2025)
Rollover view
This key's lifecycle on a time axis with phase colouring. For KSKs
the DS-at-parent overlay stripe shows when the parent-side chain of
trust was actually complete, independently of BIND's internal state
machine.
Live DNS observations and rndc dnssec -status
reports for this key. For KSKs this includes the DS lifecycle at
the parent zone (captured by key tag from the DS rdata).
File event timeline
On-disk changes to this key's K*.state / K*.key files.