Please note that there is a mistake with the time in my previous email. 
The new Key Signing Key (KSK) will be published in the DNS root zone on January 
11 around 06:00 UTC, not 00:00 UTC as originally stated.
Best regards,
-- 
Andres Pavez 
Cryptographic Key Manager 


On 1/7/25, 11:37, "dns-operations on behalf of Andres Pavez" 
<dns-operations-boun...@dns-oarc.net 
<mailto:dns-operations-boun...@dns-oarc.net> on behalf of andres.pa...@iana.org 
<mailto:andres.pa...@iana.org>> wrote:


This is a reminder that the new Key Signing Key (KSK) will be published in the 
DNS root zone starting January 11 at 00:00:00 UTC.


This will start the process of adoption of this trust anchor in RFC 5011 aware 
resolvers. We encourage operators to pay attention during this process to 
monitor for any unexpected consequences. 


Publishing the KSK is part of the process of ensuring widespread adoption of 
the KSK prior to its use in signing, currently scheduled for October 2026.


For more details, please visit: https://www.iana.org/dnssec/files 
<https://www.iana.org/dnssec/files> 


Thanks,
-- 
Andres Pavez 
Cryptographic Key Manager 








Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to