<?xml version="1.0" encoding="UTF-8"?>

<KASP>

	<Policy name="default">
		<Description>IPA default policy</Description>
		<Signatures>
			<Resign>PT5S</Resign>
			<Refresh>PT10S</Refresh>
			<Validity>
				<Default>PT1M</Default>
				<Denial>PT1M</Denial>
			</Validity>
			<Jitter>PT1S</Jitter>
			<InceptionOffset>P1D</InceptionOffset>
		</Signatures>

		<Denial>
			<NSEC3>
				<!-- <TTL>PT0S</TTL> -->
				<!-- <OptOut/> -->
				<Resalt>P100D</Resalt>
				<Hash>
					<Algorithm>1</Algorithm>
					<Iterations>5</Iterations>
					<Salt length="8"/>
				</Hash>
			</NSEC3>
		</Denial>

		<Keys>
			<!-- Parameters for both KSK and ZSK -->
			<TTL>PT10S</TTL>
			<RetireSafety>PT10S</RetireSafety>
			<PublishSafety>PT10S</PublishSafety>
			<!-- <ShareKeys/> -->
			<Purge>PT2H</Purge>

			<!-- Parameters for KSK only -->
			<KSK>
				<Algorithm length="3072">8</Algorithm>
				<Lifetime>PT1H</Lifetime>
				<Repository>SoftHSM</Repository>
			</KSK>

			<!-- Parameters for ZSK only -->
			<ZSK>
				<Algorithm length="2048">8</Algorithm>
				<Lifetime>PT15M</Lifetime>
				<Repository>SoftHSM</Repository>
				<!-- <ManualRollover/> -->
			</ZSK>
		</Keys>

		<Zone>
			<PropagationDelay>PT10S</PropagationDelay>
			<SOA>
				<TTL>PT10S</TTL>
				<Minimum>PT10S</Minimum>
				<Serial>unixtime</Serial>
			</SOA>
		</Zone>

		<Parent>
			<PropagationDelay>PT10S</PropagationDelay>
			<DS>
				<TTL>PT10S</TTL>
			</DS>
			<SOA>
				<TTL>PT10S</TTL>
				<Minimum>PT10S</Minimum>
			</SOA>
		</Parent>

	</Policy>

</KASP>
