CERT-In Advisory
CIAD-2018-0029
DNSSEC Root Zone Key Signing Key (KSK) Rollover
Original Issue Date: October 12, 2018
Description
The Internet Corporation for Assigned Names and Numbers (ICANN) has changed the cryptographic keys used in the Domain Name System Security Extensions (DNSSEC) protocol, known as the root zone Key Signing Key (KSK) on 11 October 2018.
DNSSEC is a security extension protocol, which are based on the existing DNS infrastructure. By employing digital signature technology, DNSSEC can verify the sources and Resource Records of all level DNS nameservers during DNS query process. DNSSEC not only can enhance the security of DNS and entire network infrastructure, but also can prevent different kinds of DNS attacks (such as DNS Poisoning and Spoofing).
Updating DNSSEC KSK is a crucial security step in ensuring DNSSEC-validating DNS resolvers continue to function after the rollover. Organizations that do not use DNSSEC validation will be unaffected by the rollover.
DNSSEC-signed zones have two types of keys. Zone-Signing Keys (ZSKs) that sign the zone data, and Key Signing Keys (KSK) that sign the ZSKs. In the context of the root zone, representatives from ICANN and a group "Trusted Community Representatives", oversee a key ceremony every quarter to sign a set of ZSKs used by Verisign to sign the root zone. DNSSEC-validating resolvers are configured with the public portion of the KSK, known as the root zone "trust anchor", which is used in the response validation process.
Recommendations
Resolver operators, such as Internet Service Providers (ISPs), that have enabled DNSSEC validation, will need to ensure that their systems have been updated with the new key, allowing users to validate against the new KSK as recommended by ICANN.
Resolver operators are encouraged to refer
https://www.icann.org/en/system/files/files/ksk-rollover-expect-17sep18-en.pdf
If the resolver software does not support RFC 5011 automated updates of DNSSEC "trust anchors", the "trust anchor" file must be updated manually. The official repository of the new root zone KSK can be accessed at https://data.iana.org/root-anchors/
Organizations are advised to contact their DNS resolver providers for appropriate updates and measures.
References
https://www.icann.org/en/system/files/files/ksk-rollover-quick-guide-prepare-systems-25apr18-en.pdf
https://www.icann.org/dns-resolvers-checking-current-trust-anchors
https://www.icann.org/dns-resolvers-updating-latest-trust-anchor
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|