Got a notification from my registrar that I was using an outdated DNSSEC key algorithm for my domain, so decided to re-learn how DNSSEC signing actually works in Bind.
Discovered that there's now a mode where Bind will manage keys and signing automatically. Yay! Only problem is, the domain in question was not configured that way.
Decided to use the occasion to swap over the config to that mode. Which of course caused Bind to generate new (managed) keys without doing any of the smooth gradual rollover that it otherwise implements. Oops!
Ah well, everything is set up correctly now, and it'll only be a single TTL until the whole world agrees. Should be fine; right? 😅
#DNS #DNSSEC #OpsFail