Skip to content
Esta página está disponible en español. Ver en español
Diese Seite ist auf Deutsch verfügbar. Auf Deutsch lesen
Cette page est disponible en français. Lire en français
Questa pagina è disponibile in italiano. Leggi in italiano
Esta página está disponível em português. Ler em português
Эта страница доступна на русском языке. Читать на русском
本页有中文版。 阅读中文版
tldlog.com

domain name news

Search
Menu
  • rss
  • glossary
  • stories
  • reading list
  • advertising
  • about
  • privacy
  • legal notice
en Language: English
  • Deutsch de diese Seite auf Deutsch
  • English en this page in English
  • Español es esta página en español
  • Français fr cette page en français
  • Italiano it questa pagina in italiano
  • Português pt esta página em português
  • Русский ru эта страница на русском
  • 中文 zh 本页的中文版
  • .featured
  • .policy
  • .gtld
  • .cctld
  • .market
  • .legal
  • .security
  • .business
  • .pricing
  • .all

11 oct 2026 07:26 .security link

originally published on 1 oct 2026

ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover

report an error (by email)

see your reading list

in plain words

ICANN Internet Corporation for Assigned Names and Numbers The nonprofit that coordinates the global DNS and gTLD policy. Full definition of ICANN looks after a special security key system called DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC that helps keep the internet’s address book safe from tampering. A new key, called KSK-2024, is being rolled out, and ICANN is telling the operators of systems that check this security to make sure their computers have already picked up the new key. If not, they need to fix their settings before the switch happens on 11 October 2026.

ICANN has issued a reminder to operators running DNSSEC-validating resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver, the servers that check the cryptographic signatures used to confirm that domain name system responses have not been tampered with. The reminder concerns the upcoming Root Zone Key Signing Key (KSK Key Signing Key The DNSSEC key that signs a zone's key set and is referenced by the parent zone. Full definition of KSK) rollover, scheduled for 11 October 2026, during which the cryptographic key used to sign the root of the domain name system will change to a new key, KSK-2024, identified by Key Tag 38696.

ICANN advised resolver operators to verify directly that KSK-2024 is already present in their trust anchor The key a DNSSEC resolver trusts from the start, normally the root zone's key. Full definition of trust anchor configuration rather than assuming that automatic trust-anchor update mechanisms have already installed it. Trust anchors are the cryptographic reference points that validating resolvers use to confirm the authenticity of RRSIG Resource Record Signature The DNS record that carries a DNSSEC signature for a set of records. Full definition of RRSIG; if a resolver does not have the correct current key in its trust anchor store, it may fail to validate DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS responses once the rollover takes effect, potentially causing validation failures for the domains it serves.

Operators who find that KSK-2024 is missing from their configuration were told to check whether their resolver software has automatic trust-anchor updates enabled, a mechanism defined to allow resolvers to pick up new root keys without manual intervention. Where automatic updates are not functioning or enabled, ICANN said operators should consult guidance from their specific resolver software vendor to manually update their trust anchors ahead of the rollover date.

The key rollover The planned, step-by-step replacement of a DNSSEC signing key. Full definition of key rollover is a periodic security maintenance process for the domain name system, ensuring that the cryptographic key securing the root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone can be refreshed over time. ICANN has previously carried out such rollovers and published technical resources and guidance for the process, with this reminder aimed specifically at ensuring resolver operators are prepared well before the October 2026 changeover to avoid disruption to DNSSEC validation A resolver's check that a DNS answer is correctly signed with DNSSEC. Full definition of DNSSEC validation for internet users relying on their systems.

Read on icann.org, opens another website in a new tab

The original opens on the source's website.

also covered by

  • sidn.nl in Dutch, opens another website in a new tab
  • blog.nic.cz in Czech, opens another website in a new tab
  • blog.cloudflare.com in English, opens another website in a new tab
  • bortzmeyer.org in French, opens another website in a new tab

tags

  • dns-security (tag)
  • dns (tag)
  • icann (tag)

sponsored space

This space is available for sponsorship.

Advertising on tldlog

related

  • French internet governance forum to meet in Villejuif on November 3

    link isoc.fr original in French

  • Internet's root zone DNSSEC key rotates October 11

    link blog.nic.cz original in Czech

  • Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers

    link theregister.com

recently saved

    See the full reading list
    • rss
    • glossary
    • stories
    • reading list
    • advertising
    • about
    • privacy
    • legal notice
    • tldlog on X, opens another website in a new tab

    No cookies. No trackers.