Skip to content
Esta página está disponible en español. Ver en español
tldlog.com

domain name news

Search
Menu
  • rss
  • glossary
  • stories
  • reading list
  • advertising
  • about
  • privacy
  • legal notice
en Language: English
  • Deutsch de deutsche Startseite (diese Seite gibt es nicht auf Deutsch)
  • English en this page in English
  • Español es esta página en español
  • Français fr page d'accueil en français (cette page n'a pas de version en français)
  • Italiano it pagina iniziale in italiano (questa pagina non ha una versione in italiano)
  • Português pt página inicial em português (esta página não tem versão em português)
  • Русский ru главная страница на русском (у этой страницы нет русской версии)
  • 中文 zh 中文版首页(本页没有中文版)
  • .featured
  • .policy
  • .gtld
  • .cctld
  • .market
  • .legal
  • .security
  • .business
  • .pricing
  • .all

9 oct 2026 09:56 .policy link

originally published on 9 oct 2026

Internet's root zone DNSSEC key rotates October 11

report an error (by email)

see your reading list

in plain words

The internet uses a special security key to prove that DNS Domain Name System The internet's directory that links domain names to computer addresses. Full definition of DNS answers, the system that turns website names into addresses, are genuine. On October 11, 2026 this key changes for the second time ever. People who run resolver The DNS server that looks up domain names on behalf of users. Full definition of resolver need to check their systems support the new key, or their service could break. Cloudflare made an online tool to test this.

The cryptographic key used to sign the root zone The top of the DNS, listing every TLD and its name servers. Full definition of root zone, part of the DNSSEC Domain Name System Security Extensions Digital signatures that prove DNS answers are genuine and unchanged. Full definition of DNSSEC security system, is set to rotate on October 11, 2026, according to Ondřej Filip of CZ.NIC. This will be only the second such rotation in the history of the domain name A readable internet name made of labels separated by dots. Full definition of domain name system. The current key, ID 20326, known as KSK-2017, has been in use since October 11, 2018, when it replaced the original KSK-2010. It will be replaced by a new key, ID 38696, known as KSK-2024.

Filip explains that KSK-2024 was not originally meant to be the next key. The plan had been to use KSK-2023, generated during the 49th KSK Key Signing Key The DNSSEC key that signs a zone's key set and is referenced by the parent zone. Full definition of KSK ceremony, but the hardware security module then in use, the AEP Keyper made by Ultra Electronics, was discontinued. IANA Internet Assigned Numbers Authority The functions that coordinate the root zone, IP addresses and protocol numbers. Full definition of IANA and PTI Public Technical Identifiers The ICANN affiliate that performs the IANA functions, including root zone changes. Full definition of PTI staff switched to a Luna USB 7 module from Thales, but could not transfer KSK-2023 to the new hardware, so that key was never deployed. Running two hardware security modules during the transition required new access tokens for community trusted community representatives and lengthened ceremony procedures. The replacement key, KSK-2024, was generated during the 53rd KSK ceremony and published in the root zone on January 11, 2025, starting a waiting period for resolver operators to adopt it before this weekend's cutover.

Operators running DNS resolvers are advised to confirm they already use KSK-2024/38696 so the rotation causes no disruption. Filip points to a testing mechanism defined in RFC Request for Comments A numbered document in the series recording the internet's technical standards and practices. Full definition of RFC 8509: querying the label One dot-separated part of a domain name, up to 63 characters long. Full definition of label root-key-sentinel-is-ta-38696 should return NXDOMAIN Non-Existent Domain The DNS answer meaning the requested name does not exist. Full definition of NXDOMAIN, while querying root-key-sentinel-not-ta-38696 should return SERVFAIL Server Failure The DNS answer meaning the lookup failed, often due to broken name servers or DNSSEC. Full definition of SERVFAIL. He demonstrates this using CZ.NIC's own public resolver, odvr.nic.cz, showing the expected responses. Any other result suggests a resolver either lacks RFC 8509 support, has not loaded KSK-2024, or is not validating DNSSEC at all, all of which Filip calls bad signs. Cloudflare has also published an online tool allowing network and resolver operators to check their configuration for the rotation, flagging problems with red warning indicators.

Read on blog.nic.cz, opens another website in a new tab

The original is in Czech and opens on the source's website.

also covered by

  • blog.cloudflare.com in English, opens another website in a new tab
  • sidn.nl in Dutch, opens another website in a new tab
  • icann.org in English, opens another website in a new tab
  • bortzmeyer.org in French, opens another website in a new tab

tags

  • dns (tag)
  • dns-security (tag)
  • certificates (tag)

sponsored space

This space is available for sponsorship.

Advertising on tldlog

related

  • ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover

    link icann.org

  • French internet governance forum to meet in Villejuif on November 3

    link isoc.fr original in French

  • Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers

    link theregister.com

recently saved

    See the full reading list
    • rss
    • glossary
    • stories
    • reading list
    • advertising
    • about
    • privacy
    • legal notice
    • tldlog on X, opens another website in a new tab

    No cookies. No trackers.