Hi David, At 02:12 PM 05-01-2018, David Conrad wrote:
Speaking personally, I'm hoping we can do the rollover long before 2020. The key is for
I'll reply to the question at the end of your message; this is the statement: "Each RZ KSK will be scheduled to be rolled over through a key ceremony as required, or after 5 years of operation."
the community to provide some sort of guidance to the ICANN Org about how to move forward. So far, my impression is that to date, most of the input from this mailing list has been "do it now", implying we do NOT need to assess "the impact on users" (as mentioned in https://www.icann.org/news/blog/update-on-the-root-ksk-rollover-project). This means that the plan that will be published on 31 January for public comment will say the input we have received suggests the majority of contributors do not believe we need to take potential negative impact of the KSK rollover into account.
The discussion on this mailing list has been about trust and uncertainty. Is the potential negative impact mentioned above about the "4% of the approximately 12,000 DNSSEC-validating resolvers"? If so, has there been any discussion about the data? Regards, S. Moonesamy