Public Comment

Public Comment is a vital part of our multistakeholder model. It provides a mechanism for stakeholders to have their opinions and recommendations formally and publicly documented. It is an opportunity for the ICANN community to effect change and improve policies and operations.

Ce contenu est uniquement disponible en

  • English

Name: Diksha Neeladoo B. Simmandree
Date: 2 Mar 2026
Original Public Comment: Proposed Root KSK Algorithm Rollover
Summary of Submission

The proposal requires further clarification and technical justification before proceeding. While the overall objective of transitioning the Root Zone KSK signing algorithm is acknowledged, the document lacks sufficient detail regarding key decision points, security trade-offs, and operational considerations.

In particular, the rationale for reducing the RSA 2048-bit ZSK to 1536 bits is not adequately supported, and the associated reduction in security strength is not thoroughly addressed. Alternative approaches, such as performing the ZSK algorithm transition prior to the KSK transition are not meaningfully explored. Additionally, operational elements such as key rollover sequencing, TTL expiration handling during DNSSEC transitions, and publication timing for revoked keys require deeper analysis and clearer documentation.

The publication duration for revoked keys appears insufficient, and the absence of detailed KSR composition and phase-by-phase signing information makes independent validation difficult. More transparency around the evaluation process for critical design choices would significantly improve the document and enable a more substantive technical review.

Overall, the plan would benefit from expanded technical justification, clearer operational guidance, and a more comprehensive explanation of alternatives considered before moving forward.