I am trying to set up DNSSEC for my domains. Everything seems to work but I get the following error:
DNSKEY found at child, but no DS was found at parent.
Check for DS records in parent zone
We found that none of your DNSKEY records are published at parent. All KSKs (Key Signing Keys) should have a corresponding DS record containing the digest of the key at the parent zone.
Recommendation
Publish DS records for all your DNSKEY (KSK) records in parent DNS zone. This will establish a chain of trust from the parent to your zone.
Anyone know what the problem could be?
I am using webmin for my BIND configuration and it has an option called dnssec verification and I think its done via https://dlv.isc.org/.
I made a screenshot for this: