COM zone operational announcement: DNSSEC algorithm rollover

2023-11-28 Thread Wessels, Duane via NANOG
Verisign will soon begin the transition to DNSSEC algorithm 13 (ECDSA) for the COM zone. Over the next few days, algorithm 13 signatures will start to appear in the zone, followed by the algorithm 13 DNSKEY records. We expect the DS record for the COM zone to change from algorithm 8 to

NET zone operational announcement: DNSSEC algorithm rollover

2023-10-31 Thread Wessels, Duane via NANOG
Verisign will soon begin the transition to DNSSEC algorithm 13 (ECDSA) for the NET zone. Over the next few days, algorithm 13 signatures will start to appear in the zone, followed by the algorithm 13 DNSKEY records. We expect the DS record for the NET zone to change from algorithm 8 to

Re: Root zone operational announcement: introducing ZONEMD for the root zone

2023-09-12 Thread Wessels, Duane via NANOG
Verisign and ICANN were originally planning to enable ZONEMD for the root zone tomorrow, September 13th. During a deployment to the operational testing environment, we discovered a minor issue. As a result, we, in cooperation with ICANN, have decided to postpone the production deployment of

EDU zone operational announcement: DNSSEC algorithm rollover

2023-09-12 Thread Wessels, Duane via NANOG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Verisign is pleased to announce that an algorithm 13 (ECDSA) DS record has been published for the EDU zone, and the algorithm 8 record has been removed. Over the next few days, the algorithm 8 DNSKEY records will be removed from the EDU zone,

EDU zone operational announcement: DNSSEC algorithm rollover

2023-09-05 Thread Wessels, Duane via NANOG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Verisign will soon begin the transition to DNSSEC algorithm 13 (ECDSA) for the EDU zone. Over the next few days, algorithm 13 signatures will start to appear in the zone, followed by the algorithm 13 DNSKEY records. We expect the DS record for the

Root zone operational announcement: introducing ZONEMD for the root zone

2023-07-19 Thread Wessels, Duane via NANOG
I am pleased to announce that Message Digests for DNS Zones, also known as ZONEMD, will be added to the root zone later this year. This feature, specified in RFC 8976, adds cryptographic data protections to the zone as a whole, allowing the recipient to verify the authenticity of the zone’s

Re: Contact from Verisign J root

2021-05-26 Thread Wessels, Duane via NANOG
Hernan, I will contact you off-list. DW > On May 25, 2021, at 1:17 PM, Hernan Moguilevsky wrote: > > Caution: This email originated from outside the organization. Do not click > links or open attachments unless you recognize the sender and know the > content is safe. > > Hi, > > Can

Re: Anyone from Verisign J root on the list?

2020-03-09 Thread Wessels, Duane via NANOG
> On Mar 7, 2020, at 7:31 AM, Anurag Bhatia wrote: > > Hello, > > > Was wondering if there's anyone from Verisign managing the J root? Can you > please contact me offlist. > I am facing issue with consistent ICMP filtering on "rootns-lcy3" since last > couple of weeks. > > > Thanks >

.COM Zone DNSSEC Operational Update -- ZSK length change

2019-10-14 Thread Wessels, Duane via NANOG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, Verisign is in the process of increasing the size and strength of the DNSSEC Zone Signing Keys (ZSKs) for the top-level domains that it operates. As part of this process, the ZSK for the .COM zone will be increased in size from 1024 to 1280

.ARPA Zone DNSSEC Operational Update -- ZSK length change

2019-07-09 Thread Wessels, Duane via NANOG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, Verisign is in the process of increasing the size and strength of the DNSSEC Zone Signing Keys (ZSKs) for the top-level domains that it operates. As part of this process, the ZSK for the .ARPA zone will be increased in size from 1024 to 2048

.NET Zone DNSSEC Operational Update -- ZSK length change

2019-07-09 Thread Wessels, Duane via NANOG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 All, Verisign is in the process of increasing the size and strength of the DNSSEC Zone Signing Keys (ZSKs) for the top-level domains that it operates. As part of this process, the ZSK for the .NET zone will be increased in size from 1024 to 1280