The keys to the Internet change on October 11, 2026. Are you ready?
Blog post from Cloudflare
On October 11, 2026, the DNS root’s key-signing key will change from KSK-2017 to KSK-2024, only the second such rollover and a critical event for DNSSEC, which authenticates DNS responses through a chain of cryptographic trust rooted in this key. DNSSEC-validating resolvers must trust KSK-2024, identified by key tag 38696, before the change or they could make otherwise functioning websites across all top-level domains unreachable; most website operators and users of Cloudflare DNS, 1.1.1.1, or Gateway DNS require no action. Resolvers can learn the new key automatically under RFC 5011 after observing it consistently for at least 30 days, and KSK-2024 has been published since January 2025, while Cloudflare also embedded it in its software trust anchors to reduce risks associated with upgrades or lost resolver state. Cloudflare’s readiness test uses the RFC 8509 trust-anchor sentinel protocol to determine whether a browser’s resolver recognizes the new key, although unsupported sentinel queries produce inconclusive rather than negative results. The rollover retains the RSA/SHA-256 algorithm but helps test the operational process of distributing and retiring trust anchors, with KSK-2017 scheduled for revocation and removal in 2027; it also provides preparation for possible future transitions to ECDSA and eventually post-quantum DNSSEC cryptography.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.