What are the steps required to roll my domains public KSK using a double-signing rollover procedure?
• Generate a new KSK • Include this key in your zone file and double sign file with old and new KSKs • If you are using the .gov Registar Monitor service, wait up to 24 hours for an email notification that new KSK was found and a DS RR was added to the .gov TLD. If you are not using our monitor, upload the new KSK keyset to the www.dotgov.gov website to create a DS RR on the TLD. • Continue double signed for up to 2*TTL + 1 Day while DNS propagates. • Remove old KSK from zone file and single sign only with new KSK.