The internet's root key rotates in five days. Your resolver may not be ready.
On October 11 - five days from this post - the most trusted key on the internet changes hands. KSK-2017, the key-signing key that has authenticated the DNS root zone since October 11, 2018, stops signing. KSK-2024 takes over. Eight years, to the day, and the entire trust chain of DNS runs through that swap.
The schedule is not a rumor: it is IANA's own rollover page - published January 11, 2025, trust-building via RFC 5011 through the year, and on October 11, 2026, "the successor key is scheduled to sign the zone; the current key will not."
If you run your own validating resolver, this post is for you. If you don't, it's still for you - because the failure mode when a resolver misses this window is beautifully silent: everything looks normal, and names stop resolving.
What is actually happening
DNSSEC chains trust from the root down: the root signs its DNSKEY set, your resolver holds a trust anchor - the public key it believes the root uses - and every answer below the root validates up that chain. The root zone's current key-signing key, KSK-2017 (key tag 20326), has been that anchor for eight years.
The rollover is deliberately slow, because you cannot reboot the internet's trust:
- January 11, 2025 - KSK-2024 (key tag 38696) is published alongside KSK-2017 in the root's DNSKEY record set. Nothing changes; both keys are simply there.
- From ~February 2025 - resolvers implementing RFC 5011
Comments
No comments yet. Start the discussion.