DNS Infrastructure & Naming Conventions
It’s Hard To Change The Keys To The Internet And It Involves Destroying HSM’s

It’s Hard To Change The Keys To The Internet And It Involves Destroying HSM’s

2/6/2018 · Ólafur Guðmundsson

What this post added

This post details the operational challenges and technical considerations involved in rolling the root DNSSEC Key Signing Key (KSK) according to RFC5011. It explains the importance of the KSK for the DNS chain of trust, the states of cryptographic keys, the differences in trust derivation for the root zone, and the specific reasons for the KSK rollover (testing RFC5011 and enabling algorithm switching). It also describes the history of the rollover process, including ICANN's postponement due to issues with RFC8145 adoption and Bind-9 implementations, and highlights operational realities versus protocol design assumptions regarding resolver state persistence and storage.

Read the original post ↗