Practices Configure the parent secure zone sec.soiN.jinmei.org on your first PC create parent's zone keys use dnssec-keygen add delegation to child.sec incorporate child's DS sign the parent zone (don't forget 'dnssec-enable yes' at the parent) Check if it works as intended use dig +dnssec (+norecurse) check secure delegation dig @parent_server +dnssec +norecurse => child.sec.soiN.jinmei.org