transcript
show notes
In this episode of PING we’re hearing from Duane Wessels, a fellow from Verisign who researches DNS and who we’ve had on PING before. This time Duane is discussing the history of changes of top level Key Signing Key (KSK) called “roll-over” of the KSK at the root of the DNS. This month on the 11th of October, we will complete deployment of the 3rd KSK, in the second rollover. It’s a multi-year process. This second key roll was delayed from the first rollover in 2017 by some unexpected circumstances in 2020 and 2023. The initial KSK was deployed in 2011. In October, the new key pair will enter service for the first time. The old key pair will no longer be used to sign, but will remain visible in the root until early 2027.
Duane discusses some recent DNS research work by himself and Roy Arendts from ICANN, about the observations of resolver behaviour across a root KSK roll-over. Their most recent blog article “The 2024-2026 Root Zone KSK Rollover: Updates and Observations” from July 2026 is a follow-up to their original article “The 2024-2026 Root Zone KSK Rollover: Initial Observations and Early Trends” from March 2025. It’s worth reading both articles to see how experience gained in the initial observations of the key rollover have informed subsequent research.
The DNS KSK at the root is the fundamental trust source for all subsequent DNSSSEC signed data in the global DNS. The processes around management of the private keys of this public-private key pair are described by IANA at their DNSSEC webpage and Verisign play several critical roles in the production, maintenance, distribution and use of the keying materials which come from this activity. Duane monitors this closely, both as a participant in the key ceremonies held under the auspices of ICANN/IANA, and from the vantage points Verisign has into global DNS from operations of the “J” root server anycast cloud.
Duane and Roy had the opportunity of re-analysing the behaviour of resolver systems under the key roll with greater clarity, because since the original key roll in 2017 a larger community of resolvers now use a signalling method defined in RFC8145 which indicates which trust anchors they see and are using. This has improved visibility of the uptake of the new trust anchor and shows very clearly in their time-charts of deployment of the new keying materials.
Key rolls in the DNS are not a “one and done” process, this is a multi-year activity which is about to reach it’s next most significant date later this month in October. On October the 11th, The new key will begin operations signing over the zone and the older keys will be withdrawn from signing. The new KSK has been published and listed in the root zone since January 2025, and was promoted by RFC5011 signalling in Feburary 2025.