logoalt Hacker News

tptacek • today at 5:29 PM • 0 replies • view on HN

This kind of thing makes sense when DNSSEC is brought up incidentally somewhere, but makes a lot less sense when we're discussing the solemnity and gravity of the DNSSEC key signing ceremonies, for which it is actually useful context to know that they are entirely performative.

Really the only important thing to know about DNSSEC root key rollovers is that this is only the second one they've ever done, and the last one was kind of a fiasco --- they had to delay it an entire year for logistical reasons.