logoalt Hacker News

peteetoday at 2:20 PM0 repliesview on HN

If you're a masochist you can do it manually, just make sure you have a good grasp of whats going on first[1]

Simplistically you need a DS record at your registrar, then sign your zones before publishing. You can cheat and make the KSK not expire, which saves some aggravation. I've rolled my own by hand for 10 yrs with no dnssec related downtime

[1] DNSSEC Operational Practices https://datatracker.ietf.org/doc/html/rfc6781