Security and Stability Advisory Committee (SSAC)
Контент доступен только на следующих языках
- English
SAC063 | Executive Summary for SSAC Advisory on DNSSEC Key Rollover in the Root Zone
[PDF, 479.74 KB]
This advisory addresses the unique challenges Domain Name System Security Extensions (DNSSEC) key management in the root zone poses for standard DNSSEC practices.
DNSSEC provides a mechanism for validating DNS responses, where DNS data can be cryptographically signed and validated using “keys,” which are pieces of digital information used to encrypt or decrypt data. The cryptographic keys should undergo replacements (known as “rollovers”) to minimize security risks, such as from brute force compromise, change in hardware security module vendors, or as part of regularly scheduled operations. Particularly, key management in the root zone poses unique challenges as the root is the topmost node of the DNS hierarchy from which all names are delegated, so root key compromise or loss would have security risks imposed on the entire DNS
SAC063 documents definitions and background information relating to DNSSEC, along with motivations, risks, and available mechanisms for key rollovers.
Recommendations
- Recommendation 1: Internet Corporation for Assigned Names and Numbers (ICANN) , in coordination with the other Root Zone Management Partners (United States Department of Commerce, National Telecommunications and Information Administration (NTIA), and Verisign), should immediately undertake a significant, worldwide communications effort to publicize the root zone Key-Signing Key (KSK) rollover motivation and process as widely as possible.
- Recommendation 2: ICANN staff should lead, coordinate, or otherwise encourage the creation of a collaborative, representative testbed for the purpose of analyzing behaviors of various validating resolver implementations, their versions, and their network environments (e.g., middle boxes) that may affect or be affected by a root KSK rollover, such that potential problem areas can be identified, communicated, and addressed.
- Recommendation 3: ICANN staff should lead, coordinate, or otherwise encourage the creation of clear and objective metrics for acceptable levels of “breakage” resulting from a key rollover.
- Recommendation 4: ICANN staff should lead, coordinate, or otherwise encourage the development of rollback procedures to be executed when a rollover has affected operational stability beyond a reasonable boundary.
- Recommendation 5: ICANN staff should lead, coordinate, or otherwise encourage the collection of as much information as possible about the impact of a KSK rollover to provide input to planning for future rollovers.

