Skip to content
In depthStableTechnologyFirst published 2026-10-07 12:00

DNS root key-signing key to roll over on October 11, 2026, only the second such change

The root's key-signing key, which anchors DNSSEC's chain of trust, will be replaced by KSK-2024 (key tag 38696), succeeding KSK-2017 (key tag 20326). The first rollover occurred in 2018, and the new key has been visible in the root's DNSKEY record set since January 11, 2025.

October 11, 2026

The DNS root is scheduled to perform a key-signing key rollover on this date, only the second time the root key has been changed.1

KSK-2024 (tag 38696)

The incoming root key-signing key is designated KSK-2024 and carries key tag 38696; it will replace KSK-2017, which has key tag 20326.1

30 days

Under RFC 5011, a resolver must observe a new key continuously in the signed DNSKEY records for at least 30 days before trusting it.1

Story

The DNS root's second key-signing key rollover: what changes and why it matters

1 1 1 1

1 1 1 1

1 1 1 1 1

1 1 1

1 1 1 1

1 1 1

1 1 1

1 1 1

1 1 1

1 1 1 1

1 1 1 1

Structure

Who is connected to whom
  1. 1Cloudflare
  2. partners with →Fact
    2AnthropicCompany
  3. uses →Fact
    3Apache IcebergTechnology
  4. produces →Fact
  5. supplies →Fact
  6. ← customer ofFact
    6ShopifyCompany

History

How it came to this
  1. 2018First root KSK rolloverThe initial root key-signing key rollover took place in 2018.
  2. July 2024Cloudflare incorporates KSK-2024 into default trust anchorsCloudflare incorporated KSK-2024 directly into its software's default trust anchors in July 2024.
  3. January 11, 2025KSK-2024 added to root DNSKEY record setThe root's DNSKEY record set has included KSK-2024 since January 11, 2025.
  4. NowOctober 11, 2026 Scheduled DNS root key-signing key rollover
  5. October 11, 2026The DNS root is scheduled to execute the key-signing key rollover, replacing KSK-2017 with KSK-2024.

Impact

Spreading outward, level by level
  1. Level 1DNSSEC chain of trust

    The key-signing key functions as the anchor for DNSSEC's chain of trust, enabling validating resolvers to confirm the authenticity of answers using cryptographic signatures.1

    Fact
  2. Level 2Resolvers using Cloudflare 1.1.1.1 and Gateway DNS

    Resolvers running Cloudflare's 1.1.1.1 and Gateway DNS already possess trust in the incoming KSK-2024 key, so users of those services do not need to take action for the rollover.1

    Fact
  3. Level 3Other validating resolver operators

    Operators of other validating resolvers can use the RFC 8509 sentinel protocol to test whether their resolver trusts KSK-2024 before the rollover date.

    Analysis
  4. Level 4Entire DNS ecosystem

    The rollover affects the entire DNS ecosystem, from root server operators to end-user resolvers, because without a trusted key-signing key DNSSEC validation cannot succeed.

    Analysis

Ahead

Checked automatically when due; the result goes to the track record
October 11, 2026

The DNS root is scheduled to execute the key-signing key rollover, replacing KSK-2017 with KSK-2024.

CalendarCalendar

Sources

What each source supports
1
Cloudflare Blog
2026-10-06 17:50
Original ↗
Supports 16 points
Citing: Cloudflare
2
Hacker News Front Page
2026-10-05 10:47
Original ↗
Supports 5 points
Citing: Cloudflare

Written by AI from the sources listed below: every fact was checked word for word against its source, and inference is marked apart. How we write

2026-10-06 21:32 First published