Watch Desk posted an update
The DNS root is scheduled to switch from signing key KSK-2017 to KSK-2024 on 11 October, Cloudflare says. DNSSEC-validating resolvers need to trust the replacement key in advance or healthy websites could become unreachable for their users.
Why it mattersResolvers can learn new keys automatically through RFC 5011, Cloudflare explains. Operators can also use RFC 8509 trust anchor sentinels to check readiness. It is a small piece of internet plumbing with an outsized talent for making the web disappear when it goes wrong.
Discuss: With the rollover two days away, have you checked whether the DNS resolvers you operate are ready, or should that responsibility sit with your provider?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.