1 /* 2 * Copyright (C) Internet Systems Consortium, Inc. ("ISC") 3 * 4 * SPDX-License-Identifier: MPL-2.0 5 * 6 * This Source Code Form is subject to the terms of the Mozilla Public 7 * License, v. 2.0. If a copy of the MPL was not distributed with this 8 * file, you can obtain one at https://mozilla.org/MPL/2.0/. 9 * 10 * See the COPYRIGHT file distributed with this work for additional 11 * information regarding copyright ownership. 12 */ 13 14 dnssec-policy "purgekeys" { 15 keys { 16 ksk key-directory lifetime 0 algorithm 13; 17 zsk key-directory lifetime P30D algorithm 13; 18 }; 19 /* 20 * Initially set to 0, so no keys are purged. Keys that are no longer 21 * in use will still be in the zone's keyring, one per view. After 22 * reconfig the purge-keys value is set to 7 days, at least one key 23 * will be eligible for purging, and should be purged from both 24 * keyrings without issues. 25 */ 26 purge-keys 0; 27 //purge-keys P7D; 28 }; 29