Skip to content

Understanding Trust Key Management for DNSSEC in PowerDNS Recursor #14274

Answered by omoerbeek
ryhoofr asked this question in Q&A
Discussion options

You must be logged in to vote

The root key lifecycle is very long. Once the new key data is released in 2025 by ICANN, we will start including the corresponding trust anchor (in addition to the existing one) in the recursor. It wil then take at least two years before the new key actually gets used.

https://www.icann.org/en/announcements/details/icann-to-generate-new-dns-cryptographic-key-at-april-2024-ceremony-28-02-2024-en

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
5 replies
@ryhoofr
Comment options

@mnordhoff
Comment options

@Habbie
Comment options

@Habbie
Comment options

@ryhoofr
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by ryhoofr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
4 participants