OpenDNSSEC was created as an open-source turn-key solution for DNSSEC. It secures zone data just before it is published in an authoritative name server. OpenDNSSEC takes in unsigned zones, adds the signatures and other records for DNSSEC and passes it on to the authoritative name servers for that zone. OpenDNSSEC also manages the DNSSEC keys (KSK, ZSK, and CSK), and the key rollovers and resigning of the zones.
DNS is complicated, and so is digital signing; their combination in DNSSEC is of course complex as well. The idea of OpenDNSSEC is to handle such difficulties, to relieve the administrator of them after a one-time effort for setting it up.
For our support offerings on OpenDNSSEC, please visit our Support page.