Story of first rollover to ECDSA in TLD space

Mr. Jaromír Talíř (CZ.NIC)


In CZ.NIC, we completed our third DNSSEC KSK rollover in June. It was our second algorithm rollover and it resulted in the first usage of ECDSA algorithm for DNSSEC KSK in TLD space. The talk will summarize how did we get to the situation when ECDSA algorithm is the most used DNSSEC algorithm in .CZ zone, how the conservative algorithm rollover was done and what we have learned during whole process.

Some links to the content I plan to talk about:

  • https://en.blog.nic.cz/2017/05/18/new-statistics-and-increase-in-popularity-of-elliptic-curves-in-dnssec/
  • https://en.blog.nic.cz/2018/06/01/transition-to-elliptic-curves-in-the-cz-domain/
Mr. Jaromír Talíř (CZ.NIC)

