No Answers
- Newest
- Most votes
- Most comments
Relevant content
- asked 10 months ago
- Accepted Answerasked 8 months ago
- asked 2 years ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 10 months ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated a year ago
I think part of the problem is that I have a KSK that is also being used by anther Hosted Zone (that was a mistake as I was entering the KSK). Is there a way to BYPASS the validations and simply deactivate or delete this KSK?
AWS has a new Route53 console, and some options are missing than old one.
If you "Switch to old console" on the bottom left until it is available; there is a link "Manage keys" under "DNSSEC status" for your registered domain - the documentation was not updated for the new console.
I also added a DS record with KSK and other details as shown in "View information to create DS record". I was able to recover mine by removing DS records created by the previous registrar. That allowed the KSK record to be resolved, and everything fell into place.
Troubleshooting tools I used: https://dnsviz.net https://dnssec-analyzer.verisignlabs.com