.CH/.LI DNSSEC Algorithm Rollover
Daniel Stirnimann <[email protected]> Mon, 12 Nov 2018 08:45:28 +0100
| Newsgroups | gmane.org.operators.swinog |
|---|---|
| Message-ID | <[email protected]> |
Hello, for your information, SWITCH will perform a DNSSEC algorithm rollover from RSA to ECDSA for ch. and li. ECDSA uses smaller keys and signatures than their RSA counterparts, which means responses to DNS queries are smaller. ECDSA was already standardised for use in DNSSEC in 2012. While switch.ch has been signed with ECDSA since 2016, IANA the root zone operator has only recently allowed TLDs to use it. The changes to the ch. and li. zones DNSKEY record are as following with times reported in UTC: 2018-11-21T13:30 Add new ECDSA key to DNSKEY record set 2018-12-21T13:30 Remove old RSA key from DNSKEY record set Between this interval, the chain of trust for ch. and li. will be updated in the root zone to point to the new ECDSA key only. Operators of DNSSEC validating DNS resolvers do not need to do anything. In the unlikely case that your validating DNS resolver only understands RSA but not ECDSA, then it will answer to ch. or li. queries as if they were not DNSSEC signed. You can test which DNSSEC algorithms are supported by the DNS resolver(s) configured on your system by visiting: https://rootcanary.org/test.html Best regards, Daniel Stirnimann, SWITCH -- SWITCH Daniel Stirnimann, SWITCH-CERT Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland phone +41 44 268 15 15, direct +41 44 268 16 24 [email protected], www.switch.ch _______________________________________________ swinog mailing list [email protected] http://lists.swinog.ch/cgi-bin/mailman/listinfo/swinog
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCAAGBQJb6S+cAAoJENg2VyyRLajIJ3EP/R2lOBJBc5hJ509WZIrwvoYu Tu2sbraDNpNDLV1/j/d648sjgjX95HhkbZXKcNtueoA9PIcZcign+HKzwDxyWyKU ko/qbGyY17XYwSAiiZKD1gh/HVuZ7ADyZXqARqTX+pwlF2tJ4LTHpxV2OkVQf2lQ GW+gvbZivJr2dP+hmn7XCgpCtkuRPkswoiK64pxGNfs5inFf0hdFvAsJSLJttOEh qlYmfnJKLEDSptg50EV52A+pzZ9CbPBdkXBhFtr/qAv/uMY6JN0etw+paKSu3Bde 6NI4qzLjLu5XM8mXPPSKbcjYDQ13kUvMTjVclCco/qxhPT7TBVqeosOtJpsTEaTB 8nLDE5AAEovxdsEyBT+joD5CtVa7DFnghLSKfLt5JKNbZ4ynPpqKvfk3+o47eEUi P4F5aLABrxnfyugZhVTUmR5LKcXExuKQKwrXsegL6u4a/V0/WD1DEuvWNW0f5zIM qByY4c6FnEkdJPYtETyI0H5WCsszm3xaTHARWQWgijRv27TgjG6hht3brg3Hq8aD FlHEtuigl94pH4N/LRLLUGKCLreJ6R5KJOTfq8rcAnUmimmR/NeN1Gr5dj1LCFQH oSKdHl3qri6SgjTVbVc0Jb/l9JwT892NE8ApGKs5Zz4lV/LncMeXaSIzElILpYzV PTi+SP/A1D8oBobhHjXe =VcgD -----END PGP SIGNATURE-----