Posts categorized “Uncategorized”.

Root DNSSEC Key Attestation

On June 16, 2010, I witnessed the generation of the first root zone key-signing key in the first key ceremony held by ICANN, the IANA functions operator, at its key ceremony facility in Culpeper, VA.  I attest that the following DS record corresponds to the key generated at that ceremony:

. IN DS 19036 8 2  49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5

The canonical location of the root zone trust anchor information is Also included there are supporting material and explanatory documentation.

A PGP-signed version of this attestation is available here.

Matt Larson
July 16, 2010

Episode 16

In this episode, for the first time ever, Matt and Cricket are joined by a dozen DNS dignitaries to answer a question from Alejandro Acosta about when to plug trust anchors into his name servers’ configurations and begin validating, and Bob Lee’s question about which tools to use to check his zone data and his name server’s configuration.  Then they discuss DENIC’s recent Worst Day Ever after they published a truncated zone data file for .DE.  And Mr. DNS is amazed to learn how many dynamic zone hosting services are blocked from China.

Mr. DNS sends special thanks to Dyn Inc. for their support of this Ask Mr. DNS episode.  Dyn provided the venue, the equipment and their famous New England hospitality.  Thanks also to all of the panelists for their good humor and participation.