[Dnssec-deployment] Root Zone DNSSEC Deployment Technical Status Update

Russ Mundy mundy at sparta.com
Fri Jul 16 19:02:03 EDT 2010


Congratulations to the Root DNSSEC Design Team as well as the many
people that have contributed in various ways to the definition and
development of DNSSEC over, oh, so many years.  Many people said that
this event would never happen but now the root zone is signed!!

It was very rewarding to see such an important event be accomplished
with such professionalism that most of the "Internet world" not even
realizing that the root signing had occurred - that is, itself, a
great accomplishment.


Russ Mundy

> Root Zone DNSSEC Deployment
> Technical Status Update 2010-07-16
> 
> This is the twelfth of a series of technical status updates intended
> to inform a technical audience on progress in signing the root zone
> of the DNS.
> 
> 
> RESOURCES
> 
> Details of the project, including documentation published to date,
> can be found at <http://www.root-dnssec.org/>.
> 
> We'd like to hear from you. If you have feedback for us, please
> send it to rootsign at icann.org.
> 
> 
> FULL PRODUCTION SIGNED ROOT ZONE
> 
> The transition from Deliberately-Unvalidatable Root Zone (DURZ) to
> production signed root zone took place on 2010-07-15 at 2050 UTC. The
> first full production signed root zone had SOA serial 2010071501. There
> have been no reported harmful effects.  The root zone trust anchor can
> be found at <https://data.iana.org/root-anchors/>.
> 
> 
> PLANNED DEPLOYMENT SCHEDULE
> 
> Already completed:
> 
>   2010-01-27: L starts to serve DURZ
> 
>   2010-02-10: A starts to serve DURZ
> 
>   2010-03-03: M, I start to serve DURZ
> 
>   2010-03-24: D, K, E start to serve DURZ
> 
>   2010-04-14: B, H, C, G, F start to serve DURZ
> 
>   2010-05-05: J starts to serve DURZ
> 
>   2010-06-16: First Key Signing Key (KSK) Ceremony
> 
>   2010-07-12: Second Key Signing Key (KSK) Ceremony
> 
>   2010-07-15: Distribution of validatable, production, signed root
>     zone; publication of root zone trust anchor
> 


More information about the Dnssec-deployment mailing list