ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover
in plain words
ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN looks after a special security key system called DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC that helps keep the internet’s address book safe from tampering. A new key, called KSK-2024, is being rolled out, and ICANN is telling the operators of systems that check this security to make sure their computers have already picked up the new key. If not, they need to fix their settings before the switch happens on 11 October 2026.
ICANN has issued a reminder to operators running DNSSEC-validating resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver, the servers that check the cryptographic signatures used to confirm that domain name system responses have not been tampered with. The reminder concerns the upcoming Root Zone Key Signing Key (KSK Key Signing Key The DNSSEC key that signs a zone's key set and is referenced by the parent zone. Full definition of KSK) rollover, scheduled for 11 October 2026, during which the cryptographic key used to sign the root of the domain name system will change to a new key, KSK-2024, identified by Key Tag 38696.
ICANN advised resolver operators to verify directly that KSK-2024 is already present in their trust anchor The key a DNSSEC resolver trusts from the start, normally the root zone's key. Full definition of trust anchor configuration rather than assuming that automatic trust-anchor update mechanisms have already installed it. Trust anchors are the cryptographic reference points that validating resolvers use to confirm the authenticity of RRSIG Resource Record Signature The DNS record that carries a DNSSEC signature for a set of records. Full definition of RRSIG; if a resolver does not have the correct current key in its trust anchor store, it may fail to validate DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS responses once the rollover takes effect, potentially causing validation failures for the domains it serves.
Operators who find that KSK-2024 is missing from their configuration were told to check whether their resolver software has automatic trust-anchor updates enabled, a mechanism defined to allow resolvers to pick up new root keys without manual intervention. Where automatic updates are not functioning or enabled, ICANN said operators should consult guidance from their specific resolver software vendor to manually update their trust anchors ahead of the rollover date.
The key rollover The planned, step-by-step replacement of a DNSSEC signing key. Full definition of key rollover is a periodic security maintenance process for the domain name system, ensuring that the cryptographic key securing the root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone can be refreshed over time. ICANN has previously carried out such rollovers and published technical resources and guidance for the process, with this reminder aimed specifically at ensuring resolver operators are prepared well before the October 2026 changeover to avoid disruption to DNSSEC validation A resolver's check that a DNS answer is correctly signed with DNSSEC. Full definition of DNSSEC validation for internet users relying on their systems.