DNSSEC Deployment in ARPA Children

Dave Knight dave at knig.ht
Thu Apr 29 18:09:27 CDT 2010

On 2010-04-28, at 9:29 AM, Joe Abley wrote:

> Colleagues,
> ICANN plans to begin a test deployment of DNSSEC in various zones starting on 2010-04-29:
> These zones will be signed using RSASHA256 and NSEC with 2048-bit KSKs and 1024-bit ZSKs.

The maintenance is complete, all of the zones are now DNSSEC signed.

We expect to include trust anchors for these zones following a testing period of around two weeks, given no observed or reported harmful effects.

If you observe any issues, or have any concerns please let us know at <ticket at dns.icann.org>.

Kind regards,

Dave Knight
Senior DNS Engineer, ICANN

More information about the NANOG mailing list