Dear colleagues,
Yesterday, ICANN announced that it is postponing the plan to roll, or
change, the 'apex' cryptographic key used in the DNSSEC protocol,
commonly known as the Root Zone KSK (Key Signing Key).
The KSK Rollover was due to occur on 11 October 2017. This will now be
postponed to allow more time for network operators using
DNSSEC-validating resolvers to update their systems with the new KSK.
A new date has not yet been set, however ICANN’s announcement says it is
tentatively aiming for Q1 2018:
https://www.icann.org/news/announcement-2017-09-27-en
All network operators using DNSSEC-validating resolvers are encouraged
to update their DNS resolver systems with the new KSK in preparation for
the new Rollover date.
If you have additional questions, please email ICANN:
<[email protected]>
with "KSK Rollover" in the subject line.
Regards,
Axel Pawlik
RIPE NCC