Hacker News new | ask | show | jobs
by innocenat 1487 days ago
Are there any case where DNSSEC can be kept enabled? I though it need to be disabled for transferring.
3 comments

There is, but it requires cooperation between everyone and double signing between the old and new hosting service (for a short period of time). That rarely works out in the real world.
There are some tools being worked on: https://github.com/DNSSEC-Provisioning/Multi-signer
It shouldn't be a problem, at least i never had one, if you don't change the authoritative DNS servers.