<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Aptos;
        panose-1:2 11 0 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:12.0pt;
        font-family:"Aptos",sans-serif;
        mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#467886;
        text-decoration:underline;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;
        mso-ligatures:none;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="en-JO" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal" style="text-align:justify"><a href="https://www.icann.org/resources/press-material/release-2026-05-20-en">https://www.icann.org/resources/press-material/release-2026-05-20-en</a><span lang="EN-US"><o:p></o:p></span></p>
<div style="border:none;border-bottom:solid windowtext 1.5pt;padding:0cm 0cm 1.0pt 0cm">
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">The Internet Corporation for Assigned Names and Numbers (ICANN) today announced that it is planning to change the trust anchor for the Domain Name System (DNS) on 11 October 2026. This change, known as a rollover,
is an important step in maintaining the long-term security, stability, and resiliency of the DNS.<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">The trust anchor is formally known as the Domain Name System Security Extensions (DNSSEC) root zone Key Signing Key (KSK). The KSK is the cryptographic key at the core of the DNSSEC trust anchor and is used to
verify that DNS responses are legitimate and have not been modified in transit. DNSSEC helps ensure that Internet users receive authentic DNS data when accessing websites and online services. The rollover process replaces the current KSK with a new one, to
maintain strong cryptographic security protections across the global DNS.<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">"The trust anchor rollover is a carefully coordinated process that helps safeguard the integrity of the DNS," said Kim Davies, Vice President, Internet Assigned Numbers Authority (IANA) Services and President
of Public Technical Identifiers (PTI). "While most Internet users will not notice any change, operators of DNS software should confirm that their systems are properly configured to trust the new key ahead of the rollover."<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">ICANN, through its IANA functions, manages the DNS root zone and coordinates the rollover in collaboration with partners across the global Internet community. To minimize the risk of disruption, ICANN publishes
the new KSK well in advance, allowing impacted operators sufficient time to update systems and verify that automated trust anchor update mechanisms function correctly.<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">The rollover process follows a phased implementation timeline that began in 2024 and will conclude in 2027. During this period, both the current and new KSKs remain valid, giving recursive resolvers – the systems
operated by Internet service providers, enterprises, and others that look up and verify DNS information on behalf of users – time to adopt the new trust anchor before the new KSK begins signing the root zone in October 2026 and the old key is retired in January
2027.<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">Operators running validating recursive resolvers, particularly those with manually configured trust anchors or older software, are encouraged to review their systems and verify readiness for the rollover. Failure
to update systems may result in DNS resolution failures after the rollover date.<span lang="EN-US"><o:p></o:p></span></p>
<p class="MsoNormal" style="text-align:justify"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-align:justify">More information about the KSK rollover, including operational guidance and technical resources, is available at <a href="https://www.icann.org/resources/pages/ksk-rollover-en">ICANN KSK Rollover Information Page</a>.<span lang="EN-US"><o:p></o:p></span></p>
</div>
</body>
</html>