Dear Colleagues,

IANA has published a new Certificate Authority (CA) certificate that is used 
for validating the authenticity of the DNS root zone trust anchors file.

This impacts those who verify the integrity of the DNS root zone trust anchors 
file (root-anchors.xml) using the detached signatures. Signatures chaining to 
the new certificate are expected to be published in 2028 at which time relying 
parties must validate using the new certificate.

Both the current and new certificates are available at: 
https://data.iana.org/root-anchors/icannbundle.pem 

Considerations for updating the trust anchor are described in DNSSEC Trust 
Anchor Publication for the Root Zone (RFC 9718).

Thank you,
-- 
Andres Pavez 
Cryptographic Key Manager 



Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
root-dnssec-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]

_______________________________________________
By submitting your personal data, you consent to the processing of your 
personal data for purposes of subscribing to this mailing list accordance with 
the ICANN Privacy Policy (https://www.icann.org/privacy/policy) and the website 
Terms of Service (https://www.icann.org/privacy/tos). You can visit the Mailman 
link above to change your membership status or configuration, including 
unsubscribing, setting digest-style delivery or disabling delivery altogether 
(e.g., for a vacation), and so on.

Reply via email to