跳到正文
新出现技术报道时间 2026-10-07 01:50

DNS根密钥签名密钥计划于2026年10月11日进行第二次密钥轮换

DNS根区的密钥签名密钥(KSK)将于2026年10月11日更换,用KSK-2024(密钥标签38696)替换KSK-2017,作为KSK轮换的一部分。此加密密钥是DNSSEC信任链的锚点,验证解析器必须提前信任新密钥,以避免潜在的解析失败。Cloudflare和1.1.1.1用户不受影响,因为他们的系统已经信任了新密钥。

深度阅读深度解读

为什么重要. DNSSEC 验证失败可能会在解析器未更新其信任锚点的情况下,导致全球范围内的网站可访问性中断,影响依赖安全 DNS 解析的用户和运营商的互联网可靠性。

01

影响到谁

  1. 1Cloudflare
  2. 合作 →事实
    2Anthropic公司
  3. 使用 →事实
  4. 产出 →事实
  5. 供应给 →事实
  6. ← 属于事实
    6VoidZero公司
02

证据

  • CCloudflare Blog公司披露2026-10-07 01:50
    DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    KSK-2017 and KSK-2024 both use RSA/SHA-256.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    For DNSSEC’s whole chain of trust to become post-quantum secure, signed domains, their parent zones, and the root must adopt post-quantum cryptography too.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    The test uses RFC 8509: A Root Key Trust Anchor Sentinel for DNSSEC, which we’ve implemented in 1.1.1.1 ahead of the rollover.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    RFC 8509 defines the root key trust anchor sentinel, a way to ask a supporting resolver whether it trusts a particular root key.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    For now, the next deadline is October 11.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    ICANN plans to revoke KSK-2017, remove it from the root zone, and delete its private key.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    Validating resolvers need to trust the new key before that switch.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    It will replace KSK-2017, key tag 20326, as the signer of the root’s DNSKEY set. Validating resolvers need to trust the new key before that switch.
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    For this rollover, KSK-2024 has been published in the root’s DNSKEY set since January 11, 2025. That gave resolvers with automatic trust-anchor updates time to discover and accept it ahead of the scheduled October 11, 2026 signing change. Each resolver’s waiting period starts wh…
    查看来源
  • CCloudflare Blog公司披露2026-10-07 01:50
    On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validati…
    查看来源