Dear colleagues, Yesterday, ICANN announced that it is postponing the plan to roll, or change, the 'apex' cryptographic key used in the DNSSEC protocol, commonly known as the Root Zone KSK (Key Signing Key). The KSK Rollover was due to occur on 11 October 2017. This will now be postponed to allow more time for network operators using DNSSEC-validating resolvers to update their systems with the new KSK. A new date has not yet been set, however ICANN’s announcement says it is tentatively aiming for Q1 2018: https://www.icann.org/news/announcement-2017-09-27-en All network operators using DNSSEC-validating resolvers are encouraged to update their DNS resolver systems with the new KSK in preparation for the new Rollover date. If you have additional questions, please email ICANN: <globalsupport@icann.org> with "KSK Rollover" in the subject line. Regards, Axel Pawlik RIPE NCC