What are the steps to perform a lost KSK rollover procedure?
A lost KSK will likely cause SERVFAIL errors so wait until Friday or Saturday morning to minimize disruption: • Generate a new KSK and sign zone with the new KSK and existing ZSKs. • Log into www.dotgov.gov and select Unsign Domain for this domain. • If using the .gov Registrar Monitor, wait for the standard Key Monitor email message notifying you of the DS RR creation and publish event. • (alternate) If no .gov Registrar Monitor service is enabled for this domain, then upload the keyset for the new KSK manually. • Wait 1 TTL period before possible SERVFAIL errors cease.