Main requirements to work with the DNSSEC configuration of a domain name:
- The work with DNSSEC is realized only via using a digital signature certificate;
- The activation/deactivation of the DNSSEC configuration can be done with the digital signature certificate of the registrant, the administrative contact, or the DNS and DNSSEC administrator;
- The web browser of the person who configures DNSEC should be prepared for online signing;
For more information: Certificate requirements and settings
- The domain name, for which the DNSSEC configuration shall be activated / deactivated, must be registered.
Activation of the DNSSEC configuration (adding a DS record):
- The contents of the DS record are generated via an external software. The DNS service provider should provide this content to the registrant.
- The registrant, the administrative contact, or the DNS and DNSSEC administrator fills in these data in the registry's system:
- Select the "Setup and DNSSEC" menu from the registry's system and login with a digital signature certificate of the registrant, the administrative contact, or the DNS and DNSSEC administrator.
- Go to work with the DNSSEC configuration of a specific domain name.
- Fill in the information of the DS record of the DNSSEC configuration, following the scheme below:
- The registry generates a declaration with information of the DS record, which must be signed online via the digital signature certificate of the person who is logged in the "Setup and DNSSEC" menu.
Removing a DS record from the DNSSEC configuration / deactivation of the DNSSEC configuration:
- Select the "Setup and DNSSEC" menu from the registry's system and login with a digital signature certificate of the registrant, the administrative contact, or the DNS and DNSSEC administrator.
- Go to work with the DNSSEC configuration of a specific domain name.
- Remove a specific DS record or deactivate the DNSSEC configuration. Note: If the DNSSEC configuration contains only one DS record, removing that record deactivates the entire DNSSEC configuration.
- The registry generates a declaration, which must be signed online via the digital signature certificate of the person who is logged in the "Setup and DNSSEC" menu.