NameSurfer Suite
DS records
FusionLayer
HELP
  Table of contents
   Exit help

NameSurfer 7.6.4.1


DS (Delegation Signer) records are used to verify integrity of delegated to a separate zone.

The DS record consists of the key identifier tag calculated for the key it identifies, security algorithm identifier of the key, hash algorithm identifier of the DS record itself and a digest value (hexadecimal string) of the originating DNSKEY created using the hash algorithm.

There must be one DS record for each DNSKEY of the child zone that the parent zone trusts to be genuine.