Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Can I have a government contractor or ISP sign my .gov domains?

0
Posted

Can I have a government contractor or ISP sign my .gov domains?

0

Yes. The trust model in place for .gov domains is with the POCs. Therefore, the initial KSK must be uploaded manually by a POC to ensure this is signed by the personnel responsible for the domain. We have made this very simple. All KSKs from the keyset-*.gov files that are generated as a result of the initial successful signing can be concatenated together by your contractor and emailed to you. These are public keys and are not sensitive. Upon receipt, you may log into www.dotgov.gov and upload this text file. The keys are tested, and validated against the operational domain. If they pass, then the domain(s) is/are signed. Future KSK rollovers will be automated because this initial KSK will be used for validation of future KSKs and ZSKs found in the domain. You may turn off this automation and manually upload your KSK each time. This may be desireable if you do outsource the DNS operations and need to maintain authority and trust within the government agency.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123