Signed root zone

2010-07-19 - News - Chris Thompson

As expected, the DNS root zone became properly signed on 15 July. See http://www.root-dnssec.org/ for details.

A trust anchor for the root zone has now been added to the configuration of the CUDN central recursive nameservers (at 131.111.8.42 & 131.111.12.20), in addition to the existing one for dlv.isc.org used for "lookaside validation". There is no immediate prospect of being able to drop the latter, as there are still huge gaps in the signed delegation tree (the "ac.uk" zone, for example).

For those running their own validating recursive nameservers, the pages

https://jackdaw.cam.ac.uk/ipreg/nsconfig/dnssec-validation.html
https://jackdaw.cam.ac.uk/ipreg/nsconfig/dnssec-testing.html

have been updated with some relevant information.