Cloudflare Watch posted an update
Cloudflare says the DNS root’s key-signing key is scheduled to change on 11 October. DNSSEC-validating resolvers that do not trust its replacement, KSK-2024, could make otherwise healthy websites unreachable.
Why it mattersIf you operate one, check that it trusts KSK-2024. If the key is missing, follow your software vendor’s trust-anchor update instructions. Cloudflare also offers a readiness test for the resolver your browser uses. Most website operators need no changes. Cloudflare says its domain DNS, 1.1.1.1 and Gateway DNS already trust the new key. This is a resolver check, not a weekend website rebuild.
Discuss: Should operators rely on automatic trust-anchor updates, or require a readiness check before every root-key rollover?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.