本文へ移動
新規テクノロジー報道日時 2026-10-07 01:50

DNSルートキー署名キーが2026年10月11日に2度目のロールオーバーが予定されています

DNSルートゾーンのキー署名キー(KSK)は、2026年10月11日に変更され、KSK-2017がKSK-2024(キーテグ 38696)に置き換えられます。これはKSKロールオーバーの一環です。この暗号鍵はDNSSECの信頼の鎖を固定し、検証リゾルバは事前に新しい鍵を信頼する必要があります。そうしないと解決に失敗する可能性があります。Cloudflareおよび1.1.1.1のユーザーは影響を受けません。なぜなら、彼らのシステムはすでに新しい鍵を信頼しているからです。

深掘り深掘り記事を読む

なぜ重要か. DNSSECの検証失敗は、リゾルバーがトラストアンカーを更新しない場合、ウェブサイトのアクセシビリティを世界規模で妨げる可能性があり、セキュアなDNS解決に依存するユーザーおよびオペレーターのインターネット信頼性に影響を与える可能性があります。

01

誰に影響するか

  1. 1Cloudflare
  2. と提携 →事実
    2Anthropic企業
  3. を使用 →事実
  4. を生み出す →事実
  5. に供給 →事実
  6. ← の一部事実
    6VoidZero企業
02

根拠

  • CCloudflare Blog企業開示2026-10-07 01:50
    DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    KSK-2017 and KSK-2024 both use RSA/SHA-256.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    For DNSSEC’s whole chain of trust to become post-quantum secure, signed domains, their parent zones, and the root must adopt post-quantum cryptography too.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC, which we’ve implemented in 1.1.1.1 ahead of the rollover.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    RFC 8509 defines the root key trust anchor sentinel, a way to ask a supporting resolver whether it trusts a particular root key.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    For now, the next deadline is October 11.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    ICANN plans to revoke KSK-2017, remove it from the root zone, and delete its private key.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    Validating resolvers need to trust the new key before that switch.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    It will replace KSK-2017, key tag 20326, as the signer of the root’s DNSKEY set. Validating resolvers need to trust the new key before that switch.
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025. That gave resolvers with automatic trust-anchor updates time to discover and accept it ahead of the scheduled October 11, 2026 signing change. Each resolver’s waiting period starts wh…
    出典を見る
  • CCloudflare Blog企業開示2026-10-07 01:50
    On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validati…
    出典を見る