n1. Generate keys and include them in the zone
file
n2. Sign your zone; signing
will:
usort the zone
uinsert the NXT records
uinsert SIG-s containing a
signature over each RRset
Fmade with your private key
ugenerate key-set file (used
later)
n3. Distribute the Public KEY to those that need to
be able to trust your
zone
uthey configure your key in their
resolver
uthus configuring Òsecure entry
pointÓ in the tree