The Korea Internet & Security Agency (KISA) urged domestic operators of caching Domain Name System (DNS) servers to conduct checks in advance, as the Internet Corporation for Assigned Names and Numbers (ICANN) will replace the root zone Domain Name System Security Extensions (DNSSEC) key signing key (KSK) at 0100 KST on Oct. 12.
A caching Domain Name System (DNS) connects internet users by finding the actual internet address (IP address) when they enter a domain name. The highest-level information needed to find an address is provided by the Root Zone, which contains information needed to look up top-level domain addresses such as .kr and .com.
DNS Security Extensions (DNSSEC) verifies whether such information has been forged or altered.
According to KISA, ICANN periodically replaces the key signing key to maintain the security of the root zone. This replacement is the second since DNSSEC was first applied to the root zone in 2010.
Caching DNS servers that have not reflected the new cryptographic key by the time of the replacement will fail to resolve all domain addresses within about 48 hours after 0100 KST on Oct. 12, and users of those DNS servers will be unable to access internet services. As a result, operators of caching DNS servers, including internet service providers (ISPs), must check in advance whether the new cryptographic key has been applied, KISA stressed.
Park Jeong-seop (박정섭), head of the Korea Internet Information Center at KISA, said, "About 95 percent worldwide has already reflected the new cryptographic key, so the possibility of large-scale internet disruptions is low." He added, "Still, some servers using outdated versions or where automatic renewal is not working normally may experience localized internet access disruptions, so we ask operating organizations to 반드시 check in advance whether the new cryptographic key has been reflected."