Rolling the root key
Summary
The article explains why DNS root key material must be rolled regularly and discusses the challenges and measurement techniques for KSK rollover in DNSSEC. It covers the DNS root signing key (KSK) lifecycle, RFCs guiding rollover, and the implications for post-quantum cryptography and trust anchors.