
Below is a brief describe of what the states mean:
Generate
Keys in the generate state have been created and stored but not used yet.
Publish
Keys in the publish state have been published in the zone, but are not yet considered safe to use. (i.e. They have not been in the zone long enough to have propagated through the system.)
Ready
Keys in the ready state have been published long enough that we could safely start to use them.
Active
Keys in the active state are those that are in use.
Retired
Keys in the retire state have been in use but have been replaced by a successor, they are post-published while signatures generated with them might still be in the system.
Dead
Keys in the dead state have been retired long enough for them to be safely removed from the zone.
Standby KSK states
DSSUB
The DS has possibly been submitted (if it happened automatically) but in any case we are waiting for the ds-seen command.
DSPUBLISH
The ds-seen command has been given, and we are now waiting for the various propagation delays and safety margins to pass.
DSREADY
The DS record is now considered safe to use, so the standby key is ready.
KEYPUBLISH
We have been asked to use the standby key so we have published it in the zone. Once the key has propagated through the system it will move into the active state.