chiprook
← Security
SecurityOctober 7, 2026, 16:26

IANA rotates the DNSSEC root key from KSK-2017 to KSK-2024 on October 11

On October 11, 2026, the DNSSEC root key KSK-2017 (key tag 20326), which has signed the DNS root zone since 2018, stops signing and KSK-2024 (key tag 38696) takes over. Resolvers that missed the RFC 5011 automated trust-anchor update may fail to validate names: strict validation returns SERVFAIL, opportunistic validation silently drops DNSSEC.

IANA rotates the DNSSEC root key from KSK-2017 to KSK-2024 on October 11
#IANA#DNSSEC#DNS
Read next
Security

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Security

AI agents breach trust boundaries: DNS escape, root in seconds, late warning

Security

ClickFix Lures Deploy ChainScript RAT via Polygon C2 Rotation

Security

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed