I am going to use my own names for the various period in the life of a DNSSEC key set. I know that there are some standard definitions in an RFC however I find the official names less than informative.
For this exercise all time is measured in days
|<--------------------------- Key Life ------------------------------>|
| |
|<- Lead Time ->|<--------- Active Life --------->|<- Retirement ->|
| | | |
|____ __________|__________________________________|__________________|
| | | | |
| Publish | | |
| | | |
|<- Create |<- Active Inactive ->| Delete->|