Posted on 10/10/2026 7:50:20 AM PDT by BenLurkin
On October 11, 2026, the DNS root is scheduled to change its key-signing key (KSK) for only the second time ever. This key anchors DNSSEC’s chain of trust, which lets DNS resolvers authenticate answers using cryptographic signatures. The change is called a KSK rollover. Validating resolvers need to trust the new key before the switch, as otherwise healthy websites could become unreachable.
...
Most website operators do not need to make any changes for this rollover. If you run a DNSSEC-validating resolver, check that it trusts the new root key, KSK-2024, and follow your software vendor’s instructions to update its trust anchors if the key is missing. If you use Cloudflare for your domain's DNS or rely on 1.1.1.1 and Gateway DNS, you do not need to take any action — our systems already trust KSK-2024.
A DNS resolver looks up the addresses of websites and other services for your device. DNSSEC lets it check digital signatures on DNS records to verify that they are authentic and have not been changed. The resolver also needs to check that the public keys used to verify those signatures belong to the right domains.
For cloudflare.com, this follows a chain of trust from the DNS root to .com, then to cloudflare.com. Each parent publishes a Delegation Signer (DS) record containing a fingerprint of its child’s public key. For example, .com publishes the DS record for cloudflare.com, allowing the resolver to check that domain’s key.
That chain needs a starting point. The root, however, has no parent to confirm which keys belong to it. Instead, a resolver checking DNSSEC starts with a root public key, or its fingerprint, that it already trusts. This is called a trust anchor.
(Excerpt) Read more at blog.cloudflare.com ...
|
Click here: to donate by Credit Card Or here: to donate by PayPal Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794 Thank you very much and God bless you. |
So, spam calls are no more?
I can't remember the last time that I heard this come up in casual conversation...or on a sports talk show...or a sitcom.
I don’t understand any of it.
Cloudflare... the bane of my online experience. Stupid pet tricks for VPN users.
IN ENGLISH SMALL WORDS?????
Key Signing Keys (KSKs) are used to “sign” each DNS zone. What this does is takes the name (e.g., FreeRepublic.com) and creates a unique cryptographic hash or string of mathematically unique characters to identify that record. When you type that name into your browser, you computer is told, “Hey, here’s the key for that website. Check that your hash of the key matches mine, and then proceed.” Your computer then checks that the two match, and off you go. If they don’t match, then your browser will warn you that the keys don’t match which could mean someone has “poisoned” that DNS record.
DNS is basically the Internet phonebook. Instead of having to memorize IP addresses, those IP addresses are masked with a name that’s easy to remember. DNS security (DNSSEC) adds a second check to that look up to ensure that you are going where the owner of that website intends for you to go and aren’t being tricked into going somewhere else.
The reality for this is much ado about nothing. The KSKs were likely rotated months ago with all of the downstream DNS servers being told, “Hey, upcoming rotation. Be prepared.” Those downstream DNS servers have that information cached, and when the current KSK expires, they should roll over to the new one without any trouble.
Only the most negligent DNS operators wouldn’t have this prepared, and it’s not really on the root DNS providers to make sure this change propagates.
They are improving on line security.
Yea I had problems with it too. :-)
If you're an internet end user (and not a system administrator), do nothing.
But expect less skillfully administered websites to have a few hiccups.
Ah. Thank you.
I have a generator, bathtub filled with water and a case of MREs. I’m ready.
The keys to the Internet change on October 11. Are you ready?
Y2K
Looks like DNS lookups are now encrypted. Not sure why.
It might help if I knew what DNS and DNSSEC were.
Truly amazing. Many thanks for taking the time ...
I tried to read it but all I got was blah, blah, blah. For those of us unschooled in tec terminology, what’s happening?
DNS is a domain name service. It converts domain names to ip addresses.
Like Freerepublic.com: IP address of Free Republic is 45.79.56.181.
“I have a generator, bathtub filled with water and a case of MREs. I’m ready.”
That might be overdoing it. I’m sure Freerepublic.com will still be available after the rollover.
Thank you, but I still don’t know how this will affect me. I can operate a keyboard, but computer savvy, I am not.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.