@techreport{hardaker-dnsop-intentionally-temporary-insec-01, number = {draft-hardaker-dnsop-intentionally-temporary-insec-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-hardaker-dnsop-intentionally-temporary-insec/01/}, author = {Wes Hardaker}, title = {{Intentionally Temporarily Degraded or Insecure}}, pagetotal = 8, year = 2021, month = oct, day = 21, abstract = {Performing DNSKEY algorithm transitions with DNSSEC signing is unfortunately challenging to get right in practice without decent tooling support. This document weighs the correct, completely secure way of rolling keys against an alternate, significantly simplified, method that takes a zone through an insecure state.}, }