Hello. When you activate DNSSEC for a domain, the old, unsigned zone, is left behind with a N-1 serial. This way, if you ever want to deactivate DNSSEC, the secondary DNS servers will not pull the unsigned zone after DNSSEC deactivation because it already have a N+1 serial zone that is still signed.
Not sure if it's clear... let me know if not...
Regards,
Dan
Not sure if it's clear... let me know if not...
Regards,
Dan