So, if I publish the DS and DNSKEY records I want as CDS/CDNSKEY respectively, Gandi (possibly after some configuration) will automatically pick them up, meaning that as I introduce the new KSK, it will pick itup automatically etc?
Oh that sounds very useful. I'll have to look what the complexity of creating the records will be for our infra. That'd be a super-duper way to fix things
I've had to deal with a number of KSK rollovers for the first time in production recently. I only fluffed up one of them (the most important one) :-)
I need to see if I can automate GANDI to update the KSKs