[debian-infrastructure-announce](http://lists.debian.org/debian-infrastructure-announce/)
list until such time that our zones are reachable from a
[signed root](http://www.root-dnssec.org/). KSK rollovers for our own
-child zones (www.d.o et al), once signed, will not be announced because
+child zones (www.d.o et al.), once signed, will not be announced because
we can just put proper
[DS records](http://en.wikipedia.org/wiki/List_of_DNS_record_types#DS)
in the respective parent zone.
Until we announce the first set of trust anchors on the mailinglist the
keysets present in DNS should not be considered productional. They can
-be changed at any time.
+be changed at any time, without observing standard rollover practices.
See also: