Hi, I want to create a set of keys using dnssec-keygen. I wonder if it's possible to create one KSK key and a set of ZSK's and then to sign the ZSK set with the active KSK. Finally what I want is to invoke to dnssec-signzone without using explicitly the KSK. - is there another way to proceed? - was it the functionality of dnssec-signkey? cheers, -- Victor