Root and ARPA DNSSEC operational message -- signature validity period

Wessels, Duane dwessels at
Tue Sep 6 21:33:01 UTC 2016

FYI, this work is now complete.


> On Aug 30, 2016, at 2:32 PM, Wessels, Duane <dwessels at> wrote:
> DNSSEC signatures in the Root and ARPA zones are currently given a validity
> period of 10 days.  The validity period is being increased to 13 days, per
> the recommendations of RSSAC's Report on Root Zone TTLs [1] (aka RSSAC003).
> Note that we are not aware of any cases where the 10-day signature validity
> period has caused problems for DNSSEC validators.  This is a precautionary
> measure designed to accommodate a worst-case scenario.
> This change will be implemented on September 6, 2016.  Please feel free
> to contact us at RZM at with concerns or questions, and to forward
> this notice to others who may not have already received it.
> [1]
> DW

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 495 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <>

More information about the NANOG mailing list