.CH/.LI DNSSEC Algorithm Rollover

Daniel Stirnimann <[email protected]> Mon, 12 Nov 2018 08:45:28 +0100
Newsgroups gmane.org.operators.swinog
Message-ID <[email protected]>
Hello,

for your information, SWITCH will perform a DNSSEC algorithm rollover
from RSA to ECDSA for ch. and li.

ECDSA uses smaller keys and signatures than their RSA counterparts,
which means responses to DNS queries are smaller.

ECDSA was already standardised for use in DNSSEC in 2012. While
switch.ch has been signed with ECDSA since 2016, IANA the root zone
operator has only recently allowed TLDs to use it.

The changes to the ch. and li. zones DNSKEY record are as following with
times reported in UTC:

2018-11-21T13:30 Add new ECDSA key to DNSKEY record set
2018-12-21T13:30 Remove old RSA key from DNSKEY record set

Between this interval, the chain of trust for ch. and li. will be
updated in the root zone to point to the new ECDSA key only.

Operators of DNSSEC validating DNS resolvers do not need to do anything.
In the unlikely case that your validating DNS resolver only understands
RSA but not ECDSA, then it will answer to ch. or li. queries as if they
were not DNSSEC signed.

You can test which DNSSEC algorithms are supported by the DNS
resolver(s) configured on your system by visiting:
https://rootcanary.org/test.html

Best regards,
Daniel Stirnimann, SWITCH

-- 
SWITCH
Daniel Stirnimann, SWITCH-CERT
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 15, direct +41 44 268 16 24
[email protected], www.switch.ch


_______________________________________________
swinog mailing list
[email protected]
http://lists.swinog.ch/cgi-bin/mailman/listinfo/swinog
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJb6S+cAAoJENg2VyyRLajIJ3EP/R2lOBJBc5hJ509WZIrwvoYu
Tu2sbraDNpNDLV1/j/d648sjgjX95HhkbZXKcNtueoA9PIcZcign+HKzwDxyWyKU
ko/qbGyY17XYwSAiiZKD1gh/HVuZ7ADyZXqARqTX+pwlF2tJ4LTHpxV2OkVQf2lQ
GW+gvbZivJr2dP+hmn7XCgpCtkuRPkswoiK64pxGNfs5inFf0hdFvAsJSLJttOEh
qlYmfnJKLEDSptg50EV52A+pzZ9CbPBdkXBhFtr/qAv/uMY6JN0etw+paKSu3Bde
6NI4qzLjLu5XM8mXPPSKbcjYDQ13kUvMTjVclCco/qxhPT7TBVqeosOtJpsTEaTB
8nLDE5AAEovxdsEyBT+joD5CtVa7DFnghLSKfLt5JKNbZ4ynPpqKvfk3+o47eEUi
P4F5aLABrxnfyugZhVTUmR5LKcXExuKQKwrXsegL6u4a/V0/WD1DEuvWNW0f5zIM
qByY4c6FnEkdJPYtETyI0H5WCsszm3xaTHARWQWgijRv27TgjG6hht3brg3Hq8aD
FlHEtuigl94pH4N/LRLLUGKCLreJ6R5KJOTfq8rcAnUmimmR/NeN1Gr5dj1LCFQH
oSKdHl3qri6SgjTVbVc0Jb/l9JwT892NE8ApGKs5Zz4lV/LncMeXaSIzElILpYzV
PTi+SP/A1D8oBobhHjXe
=VcgD
-----END PGP SIGNATURE-----