DNS root KSK rollover hits October 11: Cloudflare explains KSK-2024 switch and readiness test
Cloudflare Blog · rss · 2026-10-07
On October 11, 2026, the DNS root will perform only its second-ever KSK rollover, replacing KSK-2017 with KSK-2024 (key tag 38696) as the anchor of DNSSEC's chain of trust. Resolvers that don't trust the new key in advance risk making healthy websites unreachable.
Key points:
- The new key has been published in the root DNSKEY set since January 11, 2025, giving RFC 5011 auto-updating resolvers time to accept it during their mandatory 30-day waiting period.
- Cloudflare added KSK-2024 to 1.1.1.1's built-in trust anchors in July 2024, avoiding the trust-anchor loss issues seen during resolvers' software upgrades in the 2018 rollover. Users of Cloudflare DNS, 1.1.1.1 and Gateway DNS need no action.
- Most website operators are unaffected; only operators of DNSSEC-validating resolvers should verify the new key is trusted.
- Cloudflare launched a readiness test based on RFC 8509 trust anchor sentinels, using the is-ta-38696 / not-ta-38696 names (testable via dig against 1.1.1.1) to check whether your resolver trusts KSK-2024.
- The rollover keeps RSA/SHA-256; IANA targets an idealized three-year rollover interval to keep exercising the trust-anchor distribution process.
More from Infra
- Broadcom to Lend Anthropic Up to $42 Billion to Lease Its Own Chips — sourdub · 2026-10-07
- Macrocosmos pitches iota SDK for renting disaggregated compute across training and inference — markjeffrey · 2026-10-07
- AI neocloud Lambda raising up to $4B at $14.5B pre-money ahead of IPO — gharik · 2026-10-07
- AgentID launches: OIDC sign-in and email identity for AI agents — testingcatalog · 2026-10-07
- Agentic data toll: enterprise agent data services to hit ~$30B by 2030, says Bajarin — BenBajarin · 2026-10-07
- Huawei reportedly testing 256K-card Atlas-950 SuperPoD aiming for million-card compute — teortaxesTex · 2026-10-07