nAfter the key has been uploaded by
the child you have to do
an out-of band verification
uCheck if the key is in the
zone.
uCheck the self-signature; zone
owner has private key.
uCheck if the zone owner initiated
the key-exchange.
FPhone call, fax, pre-exchanged
PGP/CERTs etc
FMail to contact information
FMail to SOA address
uGenerate DS RRs from the key
RRs
FDone automatically by dnssec-signzone
if the key is stored in a
file called keyset-<child domain name>