logoalt Hacker News

Rolling the Root Key

21 points • by speckx • last Friday at 6:15 PM • 8 comments • view on HN

Comments

paaloeye • today at 3:07 PM

I'm requesting David's, Ellis's, and Adam's from Waveform: MKBHD Podcast attendance.

Context: https://www.youtube.com/watch?v=26WvISI14g0

ttul • today at 4:06 PM

Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.

Cloudflare has a nice article documents the process: https://www.cloudflare.com/learning/dns/dnssec/root-signing-...