Witnessing the Signing of the .UY Zone

June 23, 2022

Witnessing the Signing of the .UY Zone

By Carlos Martínez, LACNIC CTO

.UY, the Uruguayan TLD, updated its zone signatures using its Key Signing Key (KSK), a cryptographic key that allows signing the Domain Name System (DNS) zone and thus strengthening the system and increasing the trustworthiness of the Internet.

The KSK is used to digitally sign the set of zone-signing keys. Just as all other top-level domains (TLDs), .UY is responsible for signing its space using DNSSEC.

A globally accepted and recommended practice is to update the signatures, rolling over the keys. DNS signatures are peculiar in that their validation requires the help of the root.

(Free access, no subscription required)

A key rollover involves generating a new pair of cryptographic keys and distributing the new public key globally to all DNSSEC validating resolvers. This is a significant change, as every Internet query that uses DNSSEC relies on the KSK of the root zone to validate its destination.

If the root zone KSK is not up to date, the DNSSEC validating DNS resolvers cannot resolve DNS queries.

The mechanism that is used consists of dividing signatures in two parts: the ZSK (any change in your zone) and the KSK, which is the key used to build the trust chain upwards from .UY.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments