As many of you may know, the rollover of the DNSSEC Key Signing Key (KSK) occurred on 11 October 2018. Because of the large amount of preparation by the ICANN organization and many of ICANN's communities, the KSK rollover went quite smoothly. ICANN is grateful to all the people who made this event go well.
As expected, a small number of resolvers were not ready for the rollover. To the best of ICANN's knowledge, those resolvers were able to fix their immediate DNSSEC problems and resume their DNS service quickly.
The next step in the rollover process is to revoke the old KSK; this will happen on 11 January 2019. That step is not expected to affect any resolvers because the old KSK is not being used to sign the root zone any more. After that, the final steps of the process will remove the revoked keys from the trust anchors files and from the hardware security modules (HSMs) in ICANN's secure facilities later in 2019.