Main requirements to work with the DNSSEC configuration of a domain name:


Activation of the DNSSEC configuration (adding a DS record):
  1. The contents of the DS record are generated via an external software. The DNS service provider should provide this content to the registrant.
  2. The registrant, the administrative contact, or the DNS and DNSSEC administrator fills in these data in the registry's system:
    1. Select the "Setup and DNSSEC" menu from the registry's system and login with a digital signature certificate of the registrant, the administrative contact, or the DNS and DNSSEC administrator.
    2. Go to work with the DNSSEC configuration of a specific domain name.
    3. Fill in the information of the DS record of the DNSSEC configuration, following the scheme below:
    4. The registry generates a declaration with information of the DS record, which must be signed online via the digital signature certificate of the person who is logged in the "Setup and DNSSEC" menu.


Removing a DS record from the DNSSEC configuration / deactivation of the DNSSEC configuration:
  1. Select the "Setup and DNSSEC" menu from the registry's system and login with a digital signature certificate of the registrant, the administrative contact, or the DNS and DNSSEC administrator.
  2. Go to work with the DNSSEC configuration of a specific domain name.
  3. Remove a specific DS record or deactivate the DNSSEC configuration. Note: If the DNSSEC configuration contains only one DS record, removing that record deactivates the entire DNSSEC configuration.
  4. The registry generates a declaration, which must be signed online via the digital signature certificate of the person who is logged in the "Setup and DNSSEC" menu.