ICANN is scheduled to replace the DNSSEC root key-signing key at 1 a.m. on Oct. 12, a technical change that could prevent some internet users from reaching websites or using online services if certain DNS servers are not updated in time.

South Korea’s Korea Internet & Security Agency said the risk of a broad internet outage is low, but warned that operators of cache DNS servers should verify their systems in advance because outdated servers may fail to validate root zone data under the new key.

What is changing

The planned change involves the key-signing key, or KSK, used for the root zone of the Domain Name System Security Extensions framework. KISA said on Sept. 7 that ICANN will carry out the replacement at 1 a.m. on Oct. 12 and urged domestic cache DNS server operators to prepare beforehand.

The DNS functions as the internet’s directory, matching a domain name entered by a user with the underlying IP address needed to connect to a site or service. DNSSEC adds a layer of verification intended to confirm that this address information has not been forged or altered, and the root KSK sits at the top of that trust chain.

Why some services could fail

Problems may arise on DNS servers that continue to trust only the old key after the rollover. If those servers cannot recognize the new root KSK, they may be unable to validate root zone information correctly, which can stop normal address lookups from working.

In practice, that can look like a website failing to open even though the site itself is online. Users may see browser errors such as a message saying a site cannot be reached. The same issue can also affect email delivery or apps that need to connect to external servers.

Who needs to act

KISA said ordinary users do not need to do anything themselves ahead of the Oct. 12 change. The agency’s warning is directed instead at internet service providers, as well as companies and public institutions that run cache DNS servers.

Those operators were told to check in advance whether their systems have been updated to trust the new security key. Servers running older software or legacy configurations are the ones more likely to experience trouble after the switch.

Expected impact and next step

According to Park Jeong-seop, head of KISA’s Korea Internet Information Center, a large-scale outage across the internet is considered unlikely. Even so, he said some localized access disruptions could still occur on older servers that are not properly prepared for the rollover.

The next confirmed milestone is the root key replacement itself at 1 a.m. on Oct. 12. Whether any disruption is seen will depend on how many cache DNS operators complete their checks and updates before that time.

Source: en.bloomingbit.io