Unable to establish DNSSEC chain of trust for .com domain hosted in Route 53

0

When setting up DNSSEC for our example.com domain in the Route 53 console, I am able to complete the first part successfully. Now I need to establish the chain of trust. AWS help tells me to add a DS record. However, DS is not an option in the "type of record dropdown" when using Quick Create.

Using the wizard produces this error message: InvalidChangeBatch 400: RRSet of type DS with DNS name example.com. is not permitted in zone example.com.

Does AWS automatically add the DS records for the .com zone?

kamuzz
asked a year ago311 views
1 Answer
0

The following documents appear to support DNSSEC settings themselves.
I was wondering if there is something wrong with the way it is set up?
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-configure-dnssec.html

profile picture
EXPERT
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions