ICANN Proposes Moving the Root KSK From RSA to ECDSA
ICANN took public comment from 3 February to 6 April 2026 on moving the DNS root's key signing key from RSA/SHA-256 to ECDSA: new key in 2027, RSA retired in 2029.
Published: · 2 min read
Event date: 2026-02-03 · Source: Proposed Root KSK Algorithm Rollover, opened for comment 2026-02-03.
What happened
On 3 February 2026 ICANN opened a public comment proceeding on a proposal to change the cryptographic algorithm of the DNS root zone's key signing key. Comments were accepted until 6 April 2026, with the staff report due on 4 May 2026. The root zone has been signed with RSA-based keys and SHA-256 since DNSSEC was deployed at the root in 2010; the proposal is to move to ECDSA. The published timeline foresees the generation of a new ECDSA root KSK in 2027 and the retirement of the RSA root KSK in 2029.
ICANN asked three things of the community: whether the proposed methodology and timeline are sound, whether resolvers and servers are operationally ready for the new algorithm, and whether there are risks the plan has not considered.
This is a proposal, and the proceeding is a separate matter from the KSK rollover of 11 October 2026, which replaces one RSA key with another. We have not reviewed the staff report or any board decision that may have followed the comment period; this post describes the proposal as published on the proceeding page.
Who is affected
In the long run, every operator of a DNSSEC-validating resolver: the root trust anchor will change algorithm, and the resolver has to support ECDSA validation (check your resolver software's documentation). Authoritative DNS operators and domain owners are not asked to change anything; signing your own zone with ECDSA or RSA remains your choice.
What to do
Nothing now. If you run validating resolvers, keep them on maintained software versions and follow ICANN's root-zone announcements, since the dates above are proposed, not fixed.
How to check
The DNSSEC checker shows which algorithms a zone's keys use today, from the root down to the domain you enter.
Background
DNSSEC explained and the glossary entry on DS records cover how the chain of trust from the root works.
Sources
- ICANN, "Proposed Root KSK Algorithm Rollover", public comment opened 3 February 2026, closed 6 April 2026: https://www.icann.org/en/public-comment/proceeding/proposed-root-ksk-algorithm-rollover-03-02-2026