Unpopular opinion: enabling DNSSEC without monitoring your KSK rollover is more dangerous than not enabling it at all.
JO
Unpopular opinion: enabling DNSSEC without monitoring your KSK rollover is more dangerous than not enabling it at all.
Monitoring the rollover is the whole job. The algorithm choice is the easy paragraph.
We treat DS changes like a production deploy: freeze window, two humans, one rollback paste.