On Tue, Sep 01, 2026 at 06:06:50AM +0200, Marco d'Itri wrote:
> On Aug 22, Andres Pavez <[email protected] 
> <mailto:[email protected]>> wrote:
> 
> > Could you please review whether icannbundle.pem in the package should
> > now be updated to match the current bundle published by IANA?
> Assuming that we will not rebuild the current package, is there any other
> reason to update icannbundle.pem before either root-anchors.xml
> or root-anchors.p7s will also be updated?
> 

The short answer is: it depends.

- Yes, if you want to propagate the new icannbundle.pem.
- No, if you want to send the latest files all together.

The root-anchors.p7s signature is updated every time the root-anchors.xml file 
is updated, 
while the icannbundle.pem is updated only when we change the root CA (this is 
the 1st time since 2010).

IANA publishes the latest trust anchor file, root-anchors.xml, on its website. 
The file can be 
verified via TLS or, alternatively, out-of-band using the signature and the 
ICANN bundle.

if you validate the trust anchor information file, root-anchors.xml, using 
the root-anchors.p7s signature, you need the latest icannbundle.pem. Otherwise, 
the 
verification will fail in 2028, when we plan to start using the new root 
certificate.

The following URL describes the trust anchor files in more detail 
https://www.iana.org/dnssec/files 

Also, in 2028, we plan to update the icannbundle.pem again to remove the old 
root CA certificate.

Hope that helps to clarify.

> -- 
> ciao,
> Marco

-- 
Andres Pavez 
Cryptographic Key Manager 







Attachment: smime.p7s
Description: S/MIME cryptographic signature

Reply via email to