---
id: "5dcc1b5b-5fd1-49dd-8511-44195bae5dc2"
kind: "link"
title: "Internet's root zone DNSSEC key rotates October 11"
language: "en"
section: "icann"
date: "2026-10-09T09:56:46Z"
updated: "2026-10-11T15:36:35Z"
canonical: "https://tldlog.com/l/internets-root-zone-dnssec-key-rotates-october-11/"
origin: "master"
translations:
  es: "https://tldlog.com/es/l/clave-dnssec-zona-raiz-internet-rota-11-octubre/"
source:
  name: "blog.nic.cz"
  url: "https://blog.nic.cz/2026/10/09/rotace-klice-korenove-zony-jiz-11-rijna-zkontrolujte-si-sve-resolvery/"
  language: "cs"
  date: "2026-10-09T07:47:31Z"
---

# Internet's root zone DNSSEC key rotates October 11

## in plain words

The internet uses a special security key to prove that DNS answers, the system that turns website names into addresses, are genuine. On October 11, 2026 this key changes for the second time ever. People who run DNS resolvers need to check their systems support the new key, or their service could break. Cloudflare made an online tool to test this.

The cryptographic key used to sign the DNS root zone, part of the DNSSEC security system, is set to rotate on October 11, 2026, according to Ondřej Filip of CZ.NIC. This will be only the second such rotation in the history of the domain name system. The current key, ID 20326, known as KSK-2017, has been in use since October 11, 2018, when it replaced the original KSK-2010. It will be replaced by a new key, ID 38696, known as KSK-2024.

Filip explains that KSK-2024 was not originally meant to be the next key. The plan had been to use KSK-2023, generated during the 49th KSK ceremony, but the hardware security module then in use, the AEP Keyper made by Ultra Electronics, was discontinued. IANA and PTI staff switched to a Luna USB 7 module from Thales, but could not transfer KSK-2023 to the new hardware, so that key was never deployed. Running two hardware security modules during the transition required new access tokens for community trusted community representatives and lengthened ceremony procedures. The replacement key, KSK-2024, was generated during the 53rd KSK ceremony and published in the root zone on January 11, 2025, starting a waiting period for resolver operators to adopt it before this weekend's cutover.

Operators running DNS resolvers are advised to confirm they already use KSK-2024/38696 so the rotation causes no disruption. Filip points to a testing mechanism defined in RFC 8509: querying the label root-key-sentinel-is-ta-38696 should return NXDOMAIN, while querying root-key-sentinel-not-ta-38696 should return SERVFAIL. He demonstrates this using CZ.NIC's own public resolver, odvr.nic.cz, showing the expected responses. Any other result suggests a resolver either lacks RFC 8509 support, has not loaded KSK-2024, or is not validating DNSSEC at all, all of which Filip calls bad signs. Cloudflare has also published an online tool allowing network and resolver operators to check their configuration for the rotation, flagging problems with red warning indicators.

Source: [blog.nic.cz](https://blog.nic.cz/2026/10/09/rotace-klice-korenove-zony-jiz-11-rijna-zkontrolujte-si-sve-resolvery/)

## also covered by

- [blog.cloudflare.com](https://blog.cloudflare.com/root-ksk-2024-rollover/) (in English)
- [sidn.nl](https://www.sidn.nl/en/news-and-blogs/important-heads-up-for-dnssec-operators-root-zone-ksk-rollover-is-11-october) (in Dutch)
- [icann.org](https://www.icann.org/resources/pages/ksk-rollover-en) (in English)
- [bortzmeyer.org](https://www.bortzmeyer.org/remplacement-cle-dnssec-2026.html) (in French)
