RFC 2065:Domain Name System Security Extensions
RFC-Ref

lifetime


Click on the red underlined text to get to the source

... Section 7 reviews a variety of operational considerations including key generation, lifetime, and storage. ...


... While key lifetime is a matter of local policy, these considerations suggest that no zone key should have a lifetime ...
... lifetime is a matter of local policy, these considerations suggest that no zone key should have a lifetime significantly over four years. A reasonable maximum lifetime for zone keys ...
... zone key should have a lifetime significantly over four years. A reasonable maximum lifetime for zone keys that are kept off-line ...
... kept off-line and carefully guarded is 13 months with the intent that they be replaced every year. A reasonable maximum lifetime for end entity and useer keys that are used for IP-security ...
... are kept on line is 36 days with the intent that they be replaced monthly or more often. In some cases, an entity key lifetime of somewhat over a day may be reasonable. ...
... Signature Lifetime ...
... It is recommended that signature lifetime be a small multiple of the TTL but not less than a reasonable re-signing ...



Google
Web
RFC-Ref