Results

APNIC Pty Ltd.

10/01/2026 | Press release | Distributed by Public on 09/30/2026 17:34

[Podcast] The October 2026 root KSK roll

Inside the secure facility in Culpeper, Virginia, ICANN staff operate in an inner secure zone with restricted access.

In this episode of PING, we're hearing from Duane Wessels, a fellow at Verisign, who researches DNS and has joined us on PING before.

This time, Duane discusses the history of DNS root Key Signing Key (KSK) rollovers, the process of replacing the top-level KSK used to secure the DNS root zone. On 11 October 2026, deployment of the third KSK will be completed as part of the second KSK rollover, a process that has taken several years.

The first rollover took place in 2017, but unexpected circumstances in 2020 and 2023 delayed this second rollover. The original KSK was deployed in 2011. In October, the new key pair will enter service for the first time, while the previous key pair will stop being used for signing. However, it will remain visible in the root zone until early 2027.

Duane also discusses recent DNS research conducted with Roy Arends from ICANN, examining resolver behaviour during a root KSK rollover.

Their latest blog post, The 2024-2026 Root Zone KSK Rollover: Updates and Observations (July 2026), builds on their earlier article, The 2024-2026 Root Zone KSK Rollover: Initial Observations and Early Trends (March 2025). Together, the two articles provide an interesting view of how the researchers' understanding evolved as the rollover progressed, and how lessons from the initial observations informed their subsequent work.

The DNS root KSK is the fundamental trust source for all DNSSEC-signed data across the global DNS. The management of the private keys associated with this public-private key pair is described by IANA on its DNSSEC webpage. Verisign plays several critical roles in the generation, maintenance, distribution, and operational use of the resulting key material.

Duane follows this work closely, both as a participant in the ICANN/IANA key ceremonies and through Verisign's unique operational visibility into the global DNS via the anycast infrastructure of the J root server. This combination of hands-on involvement and large-scale operational data provides valuable insight into how resolver behaviour changes during a root KSK rollover.

Duane and Roy were also able to analyse resolver behaviour during this rollover with much greater visibility than was possible during the first root KSK rollover in 2017. Since then, a growing proportion of resolvers have implemented the signalling mechanism defined in RFC 8145, which allows validators to indicate the Trust Anchors (TA) they have installed and are using. This provides a much clearer picture of TA adoption across the Internet, with their time-series data showing the deployment of the new key material.

Key rollovers in the DNS are not a one-time event. They are carefully managed, multi-year processes, and the current rollover is about to reach its next major milestone later this month. On 11 October 2026, the new KSK will begin signing the root zone, while the previous key will be retired from active signing operations.

The new KSK has been published in the root zone since January 2025 and became eligible for automatic installation by validating resolvers through the RFC 5011 TA update process in February 2025. Since then, operators have had many months to update their systems and adopt the new TA ahead of the signing transition.

Read more about the KSK at Verisign's blog, IETF, and IANA:

You can stream and subscribe to PING via the following channels:

If you're interested in sharing your insights or research, please get in touch - we're always looking for great stories from the community. Please let us know what you think of the podcast and the APNIC Blog so we can keep improving.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of APNIC. Please note a Code of Conduct applies to this blog.

APNIC Pty Ltd. published this content on October 01, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 30, 2026 at 23:34 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]