Skip to content
NewTechnologyReported 2026-10-07 01:50

DNS root key-signing key scheduled for second-ever rollover on October 11, 2026

The DNS root zone's key-signing key (KSK) is set to change on October 11, 2026, replacing KSK-2017 with KSK-2024 (key tag 38696) as part of a KSK rollover. This cryptographic key anchors DNSSEC's chain of trust, and validating resolvers must trust the new key beforehand to avoid potential resolution failures. Cloudflare and 1.1.1.1 users are unaffected as their systems already trust the new key.

In depthRead the in-depth story

Why it matters. DNSSEC validation failures could disrupt website accessibility globally if resolvers do not update their trust anchors, affecting internet reliability for users and operators relying on secure DNS resolution.

01

Who it touches

  1. 1Cloudflare
  2. partners with →Fact
    2AnthropicCompany
  3. uses →Fact
    3Apache IcebergTechnology
  4. produces →Fact
  5. supplies →Fact
  6. ← part ofFact
    6VoidZeroCompany
02

Evidence

  • CCloudflare BlogCompany2026-10-07 01:50
    DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    KSK-2017 and KSK-2024 both use RSA/SHA-256.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    For DNSSEC’s whole chain of trust to become post-quantum secure, signed domains, their parent zones, and the root must adopt post-quantum cryptography too.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC, which we’ve implemented in 1.1.1.1 ahead of the rollover.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    RFC 8509 defines the root key trust anchor sentinel, a way to ask a supporting resolver whether it trusts a particular root key.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    For now, the next deadline is October 11.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    ICANN plans to revoke KSK-2017, remove it from the root zone, and delete its private key.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    Validating resolvers need to trust the new key before that switch.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    It will replace KSK-2017, key tag 20326, as the signer of the root’s DNSKEY set. Validating resolvers need to trust the new key before that switch.
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025. That gave resolvers with automatic trust-anchor updates time to discover and accept it ahead of the scheduled October 11, 2026 signing change. Each resolver’s waiting period starts wh…
    View source
  • CCloudflare BlogCompany2026-10-07 01:50
    On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validati…
    View source