https://www.icann.org/en/announcements/details/icann-publishes-new-dnssec-trust-anchor-to-prepare-for-2026-15-08-2024-en

 

 

The Internet Corporation for Assigned Names and Numbers (ICANN), through the 
Internet Assigned Numbers Authority functions it facilitates, recently 
published an update to the trust anchors for Domain Name System Security 
Extensions (DNSSEC).

 

DNSSEC trust anchors serve as the ultimate points of trust for the DNSSEC 
system. DNSSEC secures the DNS by validating authentic domain name data that 
has not been altered by third parties. Updates to the trust anchors require 
careful coordination among Internet infrastructure operators to ensure a 
seamless transition and maintain the security and stability of the DNS.

 

The recent update adds a new cryptographic key that is planned to be used to 
sign the DNS root zone starting in 2026. Software vendors and system package 
maintainers are encouraged to begin their processes for distributing this new 
trust anchor.

 

ICANN plans to prepublish the new cryptographic key in the DNS starting on 11 
January 2025, with a standby period of nearly two years before a rollover in 
October 2026. This provides ample opportunity to propagate the new trust anchor 
and provides the capability to roll over to it sooner should a rollover have to 
occur on an accelerated timeline.

 

Operational announcements regarding the rollover are published on the 
root-dnssec-announce mailing list. Discussion is encouraged on the separate 
ksk-rollover mailing list.

 

More information on the rollover is published at 
https://www.iana.org/dnssec/files.

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Menog mailing list
[email protected]
http://lists.menog.org/mailman/listinfo/menog

Reply via email to