The internet's root key rotates in five days. Your resolver may not be ready.
DEV Community

The internet's root key rotates in five days. Your resolver may not be ready.

On October 11 - five days from this post - the most trusted key on the internet changes hands. KSK-2017, the key-signing key that has authenticated the DNS root zone since October 11, 2018, stops signing. KSK-2024 takes over. Eight years, to the day, and the entire trust chain of DNS runs through that swap.

The schedule is not a rumor: it is IANA's own rollover page - published January 11, 2025, trust-building via RFC 5011 through the year, and on October 11, 2026, "the successor key is scheduled to sign the zone; the current key will not."

If you run your own validating resolver, this post is for you. If you don't, it's still for you - because the failure mode when a resolver misses this window is beautifully silent: everything looks normal, and names stop resolving.

What is actually happening

DNSSEC chains trust from the root down: the root signs its DNSKEY set, your resolver holds a trust anchor - the public key it believes the root uses - and every answer below the root validates up that chain. The root zone's current key-signing key, KSK-2017 (key tag 20326), has been that anchor for eight years.

The rollover is deliberately slow, because you cannot reboot the internet's trust:

  • January 11, 2025 - KSK-2024 (key tag 38696) is published alongside KSK-2017 in the root's DNSKEY record set. Nothing changes; both keys are simply there.
  • From ~February 2025 - resolvers implementing RFC 5011
Read on DEV Community ↗ ← Back to News

Comments

No comments yet. Start the discussion.