Feb 8 – 9, 2024 Workshop
Embassy Suites Charlotte Uptown
US/Eastern timezone

Verisign's Transition to ECDSA

Feb 8, 2024, 2:45 PM
Salon A/B (Embassy Suites Charlotte Uptown)

Salon A/B

Embassy Suites Charlotte Uptown

401 East Martin Luther King Jr Blvd Charlotte NC 28202 United States
In-Person Standard Presentation Main Session OARC 42 Day 1


Duane Wessels (Verisign)


In 2023, Verisign changed the DNSSEC signing algorithm for the .EDU, .NET., and .COM TLDs from RSA (algorithm 8) to ECDSA (algorithm 13). In this presentation we describe our conservative, double-signing approach to the algorithm rollovers, and our observations on how DNS query traffic before, during, and after each rollover.

In particular, we make observations on how DNS glue truncation policies impact response sizes, and on the population of recursive resolvers that are unable to fall back to TCP for large, truncated UDP responses. We'll show metrics that we developed for our real-time dashboards to remain informed of potential problems and discuss options for mitigating any significant impacts.

Talk duration

Primary author

Duane Wessels (Verisign)

Presentation materials