[dns-operations] [Ext] Reminder: New KSK Publication in DNS Root Zone

Andres Pavez andres.pavez at iana.org
Tue Jan 7 20:18:20 UTC 2025


Please note that there is a mistake with the time in my previous email. 
The new Key Signing Key (KSK) will be published in the DNS root zone on January 11 around 06:00 UTC, not 00:00 UTC as originally stated.
Best regards,
-- 
Andres Pavez 
Cryptographic Key Manager 


On 1/7/25, 11:37, "dns-operations on behalf of Andres Pavez" <dns-operations-bounces at dns-oarc.net <mailto:dns-operations-bounces at dns-oarc.net> on behalf of andres.pavez at iana.org <mailto:andres.pavez at iana.org>> wrote:


This is a reminder that the new Key Signing Key (KSK) will be published in the DNS root zone starting January 11 at 00:00:00 UTC.


This will start the process of adoption of this trust anchor in RFC 5011 aware resolvers. We encourage operators to pay attention during this process to monitor for any unexpected consequences. 


Publishing the KSK is part of the process of ensuring widespread adoption of the KSK prior to its use in signing, currently scheduled for October 2026.


For more details, please visit: https://www.iana.org/dnssec/files <https://www.iana.org/dnssec/files> 


Thanks,
-- 
Andres Pavez 
Cryptographic Key Manager 








-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4863 bytes
Desc: not available
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20250107/56daf133/attachment.bin>


More information about the dns-operations mailing list