Alphabetical glossary

K glossary terms

9 definitions beginning with K.

9 terms

DHCP

Kea

An open-source DHCPv4, DHCPv6, and dynamic DNS server developed by ISC. It uses a modular architecture, APIs, hooks, and external database options.

Read definition
Security

Kerberos

A ticket-based authentication protocol widely used by Active Directory. DNS secure dynamic updates can use Kerberos through GSS-TSIG.

Read definition
DNSSEC

Key ceremony

A controlled process for generating, activating, backing up, rolling, or retiring cryptographic keys, often with documented roles and evidence. It is especially important for high-trust trust anchors and KSKs.

Read definition
DNSSEC

Key rollover

The planned replacement of a DNSSEC key while maintaining a valid chain of trust and continuous validation. Rollovers require timing that accounts for TTLs, signature validity, parent DS updates, and publication overlap.

Read definition
DNSSEC

Key signing key (KSK)

An operational role for a DNSKEY that primarily signs the DNSKEY RRset. A parent DS normally points to a KSK, though DNSSEC protocol flags do not fully enforce operational roles.

Read definition
DNSSEC

Key tag

A 16-bit value calculated from a DNSKEY and included in RRSIG and DS records to help identify the relevant key. It is an index hint, not a globally unique identifier.

Read definition
DNS

Knot DNS

An open-source authoritative DNS server developed by CZ.NIC, designed for high-performance authoritative service and DNSSEC operation. It is distinct from Knot Resolver.

Read definition
DNS

Knot Resolver

An open-source caching and validating recursive resolver developed by CZ.NIC. It supports modular policy and modern DNS transports.

Read definition
DNSSEC

KSK

The common abbreviation for Key Signing Key. It is usually the key whose digest is represented by the parent DS record.

Read definition