DNSSEC for a domain you host yourself: sign the zone, then the DS record
DNSSEC has two halves that live in different places. Sign the zone on your nameserver, publish the DS at the registrar, and undo it in reverse.
Two halves, in two places
DNSSEC lets a resolver check that a DNS answer really came from the zone's owner and was not altered on the way. It does that with signatures, and with a chain of trust that runs from the root, through the registry for .com or .net, down to your zone.
That chain has two links you control, and they live in different places.
- The signed zone lives on your nameserver. The server holds a key and signs every record with it.
- The DS record lives at your registrar, who passes it to the registry. It is a fingerprint of your key, and it is what tells the world "this zone is signed, and this is the key to trust".
Almost every DNSSEC outage is these two halves disagreeing.
The order that cannot break anything
Sign first. A signed zone with no DS record is harmless. Resolvers see no DS at the registry, treat the zone as unsigned, and ignore the signatures. Nothing changes for visitors.
Publish the DS second. Once the DS is at the registry, validating resolvers start checking. If the zone is signed with the matching key, they accept the answers. If it is not, they refuse them, and the domain stops resolving for everyone behind such a resolver.
So a DS record published before the zone is signed, or for the wrong key, takes the domain offline. Signing before the DS never does.
Signing a zone in KLYRN
This applies to domains hosted on the server's own nameservers, which KLYRN runs on PowerDNS. Since 1.0.4, sign a zone from Settings, Nameservers, or from the command line:
klyrn dns dnssec example.com on
klyrn dns dnssec example.com
The first time any zone is signed, the nameserver restarts once to switch signing support on. The second command prints the state and the DS record to give the registrar. Immediately after signing, the state reads: signed here, not yet anchored at the registrar.
If the zone is held at Cloudflare or another DNS provider instead, signing is that provider's job and this command is not the place for it.
Adding the DS at the registrar
Find the DNSSEC section in the registrar's control panel for the domain. Paste the DS record KLYRN printed. Some registrars ask for its four parts in separate fields: key tag, algorithm, digest type and digest. They are the four values of the record, in that order.
Then wait for the registry to publish it, and check from outside:
dig +short DS example.com
dig +dnssec example.com
The first shows the DS the world sees. The second should show signatures alongside the answer. Run klyrn dns dnssec example.com again: the state becomes signed and anchored at the registrar. If the registrar holds a DS for a different key, KLYRN says that instead and prints the one to replace it with.
Switching it off, in reverse
The rule that matters most: never switch signing off while the DS is still at the registrar. The registry would keep telling resolvers the zone is signed while the zone has no signatures, and they would refuse every answer.
Undo it in the opposite order to the way you set it up:
- Remove the DS record at the registrar.
- Wait for it to disappear. A day is safe.
- Switch signing off.
KLYRN enforces this. It asks a public resolver whether the DS is still published, and refuses to unsign a zone that still has one, saying that the domain would stop resolving. If it cannot check at that moment, it refuses too, and asks you to try again in a minute.
The same order applies when you move a signed domain to another nameserver or another host: remove the DS, wait, move, sign at the new place, publish the new DS.