Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-77714

New 2024 trust anchor key for DNSSEC

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-7.9.z, rhel-8.10.z, rhel-9.6, rhel-10.0
    • None
    • DNSSEC root key 2024
    • Moderate
    • rhel-net-perf
    • ssg_core_services
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Hide

      Both new key is provided for new installations and also for already running installation, which receives the update.

      Requires upstream DNSSEC-aware forwarder or direct access to root servers.

      Show
      Both new key is provided for new installations and also for already running installation, which receives the update. Requires upstream DNSSEC-aware forwarder or direct access to root servers.
    • None
    • None
    • None

      Description

      New DNSSEC trust anchor key were generated and is already published. New installations should have the key present. As an operator of DNSSEC validating server or client I want to have keys updated.

      What SSTs and Layered Product teams should review this?

      • rhel-sst-cs-net-and-perf-services
      • rhel-sst-cs-plumbers

      Dates

      2025-01-11 Published new KSK key.
      2026-10-11 Announced date of key rollover, started signing DNS records with new key

              pemensik@redhat.com Petr Mensik
              pemensik@redhat.com Petr Mensik
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: