CINXE.COM
Root KSK Ceremonies
<!doctype html> <html> <head> <title>Root KSK Ceremonies</title> <meta charset="utf-8" /> <meta http-equiv="Content-type" content="text/html; charset=utf-8" /> <meta name="viewport" content="width=device-width, initial-scale=1" /> <link rel="stylesheet" href="/_css/2022/iana_website.css"/> <link rel="shortcut icon" type="image/ico" href="/_img/bookmark_icon.ico"/> <script type="text/javascript" src="/_js/jquery.js"></script> <script type="text/javascript" src="/_js/iana.js"></script> </head> <body> <header> <div id="header"> <div id="logo"> <a href="/"><img src="/_img/2022/iana-logo-header.svg" alt="Homepage"/></a> </div> <div class="navigation"> <ul> <li><a href="/domains">Domains</a></li> <li><a href="/protocols">Protocols</a></li> <li><a href="/numbers">Numbers</a></li> <!-- <li><a href="/news">News</a></li>--> <li><a href="/about">About</a></li> </ul> </div> </div> </header> <div id="body"> <article class="hemmed sidenav"> <main> <h1>Key Signing Ceremonies</h1> <p>Ceremonies are usually conducted four times a year to perform operations using the Root Key Signing Key, and involving <a href="/dnssec/tcrs">Trusted Community Representatives</a>. In a typical ceremony, the KSK is used to sign a set of operational ZSKs that will be used for a three month period to sign the DNS root zone. Other operations that may occur during ceremonies include installing new cryptographic officers, replacing hardware, or generating or replacing a KSK.</p> <h2>Ceremonies</h2> <table class="iana-table"> <thead> <tr> <th>Date</th> <th>Ceremony</th> <th>Agenda</th> </tr> </thead> <tr> <td>2025-04-24</td> <td><a href="/dnssec/ceremonies/57"> KSK Ceremony 57</a></td> <td>Sign 2025Q3 ZSKs</td> </tr> <tr> <td>2025-02-12</td> <td><a href="/dnssec/ceremonies/56"> KSK Ceremony 56</a></td> <td>Sign 2025Q2 ZSKs; Replace CO3 & CO4 (West)</td> </tr> <tr> <td>2024-10-17</td> <td><a href="/dnssec/ceremonies/55"> KSK Ceremony 55</a></td> <td>Sign 2025Q1 ZSKs; Replace CO1 (East)</td> </tr> <tr> <td>2024-07-17</td> <td><a href="/dnssec/ceremonies/54"> KSK Ceremony 54</a></td> <td>Sign 2024Q4 ZSKs; Introduce Successor HSMs; Import KSK-2024</td> </tr> <tr> <td>2024-04-26</td> <td><a href="/dnssec/ceremonies/53-2"> KSK Ceremony 53-2</a></td> <td>Introduce Successor HSMs; Generate KSK-2024</td> </tr> <tr> <td>2024-04-25</td> <td><a href="/dnssec/ceremonies/53-1"> KSK Ceremony 53-1</a></td> <td>Sign 2024Q3 ZSKs; Replace RKSHs 1 & 6; Reissue RKSH Cards</td> </tr> <tr> <td>2024-02-14</td> <td><a href="/dnssec/ceremonies/52"> KSK Ceremony 52</a></td> <td>Sign 2024Q2 ZSKs; Introduce HSM8W</td> </tr> <tr> <td>2023-11-30</td> <td><a href="/dnssec/ceremonies/51"> KSK Ceremony 51</a></td> <td>Sign 2024Q1 ZSKs; Replace CO5 (East); Introduce HSM7E & HSM8E</td> </tr> <tr> <td>2023-07-19</td> <td><a href="/dnssec/ceremonies/50"> KSK Ceremony 50</a></td> <td>Sign 2023Q4 ZSKs; Import KSK-2023</td> </tr> <tr> <td>2023-04-27</td> <td><a href="/dnssec/ceremonies/49"> KSK Ceremony 49</a></td> <td>Sign 2023Q3 ZSKs; Generate KSK-2023; Replace CO6 (East)</td> </tr> <tr> <td>2023-02-01</td> <td><a href="/dnssec/ceremonies/48"> KSK Ceremony 48</a></td> <td>Sign 2023Q2 ZSKs; Reissue CO Cards; Replace CO2 (West); Introduce HSM7W</td> </tr> <tr> <td>2022-11-03</td> <td><a href="/dnssec/ceremonies/47"> KSK Ceremony 47</a></td> <td>Sign 2023Q1 ZSKs; Replace CO2 & CO7 (East)</td> </tr> <tr> <td>2022-08-17</td> <td><a href="/dnssec/ceremonies/46"> KSK Ceremony 46</a></td> <td>Sign 2022Q4 ZSKs; Replace CO6 (West); Destroy HSMs 3&4 (West)</td> </tr> <tr> <td>2022-05-12</td> <td><a href="/dnssec/ceremonies/45"> KSK Ceremony 45</a></td> <td>Sign 2022Q3 ZSKs; Reissue CO Cards; Replace 2 TCRs; Destroy HSM4 (East)</td> </tr> <tr> <td>2022-02-16</td> <td><a href="/dnssec/ceremonies/44"> KSK Ceremony 44</a></td> <td>Sign 2022Q2 ZSKs; Introduce HSM6W</td> </tr> <tr> <td>2021-10-14</td> <td><a href="/dnssec/ceremonies/43"> KSK Ceremony 43</a></td> <td>Sign 2022Q1 ZSKs; Introduce HSM6E</td> </tr> <tr> <td>2021-02-11</td> <td><a href="/dnssec/ceremonies/42"> KSK Ceremony 42</a></td> <td>Sign 2021Q2-2021Q4 ZSKs</td> </tr> <tr> <td>2020-04-23</td> <td><a href="/dnssec/ceremonies/41"> KSK Ceremony 41</a></td> <td>Sign 2020Q3-2021Q1 ZSKs</td> </tr> <tr> <td>2020-02-16</td> <td><a href="/dnssec/ceremonies/40"> KSK Ceremony 40</a></td> <td>Sign 2020Q2 ZSKs</td> </tr> <tr> <td>2019-11-14</td> <td><a href="/dnssec/ceremonies/39"> KSK Ceremony 39</a></td> <td>Sign 2020Q1 ZSKs; Destroy HSM3 (East)</td> </tr> <tr> <td>2019-08-14</td> <td><a href="/dnssec/ceremonies/38"> KSK Ceremony 38</a></td> <td>Sign 2019Q4 ZSKs; KSK Delete; Destroy HSMs 1&2; Introduce HSM5W</td> </tr> <tr> <td>2019-05-16</td> <td><a href="/dnssec/ceremonies/37"> KSK Ceremony 37</a></td> <td>Sign 2019Q3 ZSKs; KSK Delete; Destroy HSMs 1&2; Introduce HSM5E</td> </tr> <tr> <td>2019-02-27</td> <td><a href="/dnssec/ceremonies/36"> KSK Ceremony 36</a></td> <td>Sign 2019Q2 ZSKs</td> </tr> <tr> <td>2018-11-15</td> <td><a href="/dnssec/ceremonies/35"> KSK Ceremony 35</a></td> <td>Sign 2019Q1 ZSKs</td> </tr> <tr> <td>2018-08-15</td> <td><a href="/dnssec/ceremonies/34"> KSK Ceremony 34</a></td> <td>Sign 2018Q4 ZSKs</td> </tr> <tr> <td>2018-04-11</td> <td><a href="/dnssec/ceremonies/33"> KSK Ceremony 33</a></td> <td>Sign 2018Q3 ZSKs</td> </tr> <tr> <td>2018-02-07</td> <td><a href="/dnssec/ceremonies/32"> KSK Ceremony 32</a></td> <td>Sign 2018Q2 ZSKs; Destruction Test HSM1 (West)</td> </tr> <tr> <td>2017-10-18</td> <td><a href="/dnssec/ceremonies/31"> KSK Ceremony 31</a></td> <td>Sign 2018Q1 ZSKs; Replace RKSH 3</td> </tr> <tr> <td>2017-08-17</td> <td><a href="/dnssec/ceremonies/30"> KSK Ceremony 30</a></td> <td>Sign 2017Q4 ZSKs</td> </tr> <tr> <td>2017-04-27</td> <td><a href="/dnssec/ceremonies/29"> KSK Ceremony 29</a></td> <td>Sign 2017Q3 ZSKs</td> </tr> <tr> <td>2017-02-02</td> <td><a href="/dnssec/ceremonies/28"> KSK Ceremony 28</a></td> <td>Sign 2017Q2 ZSKs; Import KSK-2017</td> </tr> <tr> <td>2016-10-27</td> <td><a href="/dnssec/ceremonies/27"> KSK Ceremony 27</a></td> <td>Sign 2017Q1 ZSKs; Generate KSK-2017; Zeroize HSMs 1&2 (East)</td> </tr> <tr> <td>2016-08-11</td> <td><a href="/dnssec/ceremonies/26"> KSK Ceremony 26</a></td> <td>Sign 2016Q4 ZSKs; Zeroize HSMs 1&2 (West)</td> </tr> <tr> <td>2016-05-12</td> <td><a href="/dnssec/ceremonies/25"> KSK Ceremony 25</a></td> <td>Sign 2016Q3 ZSKs</td> </tr> <tr> <td>2016-02-11</td> <td><a href="/dnssec/ceremonies/24"> KSK Ceremony 24</a></td> <td>Sign 2016Q2 ZSKs; Replace CO6 (West)</td> </tr> <tr> <td>2015-11-12</td> <td><a href="/dnssec/ceremonies/23"> KSK Ceremony 23</a></td> <td>Sign 2016Q1 ZSKs</td> </tr> <tr> <td>2015-08-13</td> <td><a href="/dnssec/ceremonies/22"> KSK Ceremony 22</a></td> <td>Sign 2015Q4 ZSKs; Introduce HSMs 3&4 (West); Replace CO1 (West)</td> </tr> <tr> <td>2015-04-09</td> <td><a href="/dnssec/ceremonies/21"> KSK Ceremony 21</a></td> <td>Sign 2015Q3 ZSKs; Introduce HSMs 3&4 (East)</td> </tr> <tr> <td>2015-01-22</td> <td><a href="/dnssec/ceremonies/20"> KSK Ceremony 20</a></td> <td>Sign 2015Q2 ZSKs</td> </tr> <tr> <td>2014-11-20</td> <td><a href="/dnssec/ceremonies/19"> KSK Ceremony 19</a></td> <td>Sign 2015Q1 ZSKs</td> </tr> <tr> <td>2014-08-14</td> <td><a href="/dnssec/ceremonies/18"> KSK Ceremony 18</a></td> <td>Sign 2014Q4 ZSKs; Replace CO5 (West)</td> </tr> <tr> <td>2014-04-17</td> <td><a href="/dnssec/ceremonies/17"> KSK Ceremony 17</a></td> <td>Sign 2014Q3 ZSKs</td> </tr> <tr> <td>2014-02-13</td> <td><a href="/dnssec/ceremonies/16"> KSK Ceremony 16</a></td> <td>Sign 2014Q2 ZSKs</td> </tr> <tr> <td>2013-10-24</td> <td><a href="/dnssec/ceremonies/15"> KSK Ceremony 15</a></td> <td>Sign 2014Q1 ZSKs</td> </tr> <tr> <td>2013-08-07</td> <td><a href="/dnssec/ceremonies/14"> KSK Ceremony 14</a></td> <td>Sign 2013Q4 ZSKs</td> </tr> <tr> <td>2013-05-02</td> <td><a href="/dnssec/ceremonies/13"> KSK Ceremony 13</a></td> <td>Sign 2013Q3 ZSKs; Replace CO5 (East)</td> </tr> <tr> <td>2013-02-12</td> <td><a href="/dnssec/ceremonies/12"> KSK Ceremony 12</a></td> <td>Sign 2013Q2 ZSKs</td> </tr> <tr> <td>2012-11-12</td> <td><a href="/dnssec/ceremonies/11"> KSK Ceremony 11</a></td> <td>Sign 2013Q1 ZSKs</td> </tr> <tr> <td>2012-07-26</td> <td><a href="/dnssec/ceremonies/10"> KSK Ceremony 10</a></td> <td>Sign 2012Q4 ZSKs</td> </tr> <tr> <td>2012-05-22</td> <td><a href="/dnssec/ceremonies/9"> KSK Ceremony 9</a></td> <td>Sign 2012Q3 ZSKs</td> </tr> <tr> <td>2012-02-02</td> <td><a href="/dnssec/ceremonies/8"> KSK Ceremony 8</a></td> <td>Sign 2012Q2 ZSKs</td> </tr> <tr> <td>2011-09-30</td> <td><a href="/dnssec/ceremonies/7"> KSK Ceremony 7</a></td> <td>Sign 2012Q1 ZSKs</td> </tr> <tr> <td>2011-07-20</td> <td><a href="/dnssec/ceremonies/6"> KSK Ceremony 6</a></td> <td>Sign 2011Q4 ZSKs</td> </tr> <tr> <td>2011-05-11</td> <td><a href="/dnssec/ceremonies/5"> KSK Ceremony 5</a></td> <td>Sign 2011Q3 ZSKs</td> </tr> <tr> <td>2011-02-07</td> <td><a href="/dnssec/ceremonies/4"> KSK Ceremony 4</a></td> <td>Sign 2011Q2 ZSKs</td> </tr> <tr> <td>2010-11-01</td> <td><a href="/dnssec/ceremonies/3"> KSK Ceremony 3</a></td> <td>Sign 2011Q1 ZSKs</td> </tr> <tr> <td>2010-07-12</td> <td><a href="/dnssec/ceremonies/2"> KSK Ceremony 2</a></td> <td>Instantiate El Segundo KMF; Import KSK-2010; Sign 2010Q4 ZSKs</td> </tr> <tr> <td>2010-06-16</td> <td><a href="/dnssec/ceremonies/1"> KSK Ceremony 1</a></td> <td>Instantiate Culpeper KMF; Generate KSK-2010; Sign 2010Q3 ZSKs</td> </tr> </table> </main> <nav id="sidenav"> <div class="navigation_box"> <h2>Domain Names</h2> <ul> <li id="nav_dom_top"><a href="/domains">Overview</a></li> <li id="nav_dom_root"><a href="/domains/root">Root Zone Management</a></li> <ul id="nav_dom_root_sub"> <li id="nav_dom_root_top"><a href="/domains/root">Overview</a></li> <li id="nav_dom_root_db"><a href="/domains/root/db">Root Database</a></li> <li id="nav_dom_root_files"><a href="/domains/root/files">Hint and Zone Files</a></li> <li id="nav_dom_root_manage"><a href="/domains/root/manage">Change Requests</a></li> <li id="nav_dom_root_procedures"><a href="/domains/root/help">Instructions & Guides</a></li> <li id="nav_dom_root_servers"><a href="/domains/root/servers">Root Servers</a></li> </ul> <li id="nav_dom_int"><a href="/domains/int">.INT Registry</a></li> <ul id="nav_dom_int_sub"> <li id="nav_dom_int_top"><a href="/domains/int">Overview</a></li> <li id="nav_dom_int_manage"><a href="/domains/int/manage">Register/modify an .INT domain</a></li> <li id="nav_dom_int_policy"><a href="/domains/int/policy">Eligibility</a></li> </ul> <li id="nav_dom_arpa"><a href="/domains/arpa">.ARPA Registry</a></li> <li id="nav_dom_idn"><a href="/domains/idn-tables">IDN Practices Repository</a></li> <ul id="nav_dom_idn_sub"> <li id="nav_dom_idn_top"><a href="/domains/idn-tables">Overview</a></li> <!-- <li id="nav_dom_idn_tables"><a href="/domains/idn-tables/db">Tables</a></li> --> <li id="nav_dom_idn_submit"><a href="/procedures/idn-repository.html">Submit a table</a></li> </ul> <li id="nav_dom_dnssec"><a href="/dnssec">Root Key Signing Key (DNSSEC)</a></li> <ul id="nav_dom_dnssec_sub"> <li id="nav_dom_dnssec_top"><a href="/dnssec">Overview</a></li> <li id="nav_dom_dnssec_ksk"><a href="/dnssec/files">Trust Anchors and Rollovers</a></li> <li id="nav_dom_dnssec_ceremonies"><a href="/dnssec/ceremonies">Key Signing Ceremonies</a></li> <li id="nav_dom_dnssec_dps"><a href="/dnssec/procedures">Policies & Procedures</a></li> <li id="nav_dom_dnssec_tcrs"><a href="/dnssec/tcrs">Community Representatives</a></li> <li id="nav_dom_dnssec_archive"><a href="/dnssec/archive">Project Archive</a></li> </ul> <li id="nav_dom_special"><a href="/domains/reserved">Reserved Domains</a></li> </ul> </div> </nav> </article> </div> <footer> <div id="footer"> <table class="navigation"> <tr> <td class="section"><a href="/domains">Domain Names</a></td> <td class="subsection"> <ul> <li><a href="/domains/root">Root Zone Registry</a></li> <li><a href="/domains/int">.INT Registry</a></li> <li><a href="/domains/arpa">.ARPA Registry</a></li> <li><a href="/domains/idn-tables">IDN Repository</a></li> </ul> </td> </tr> <tr> <td class="section"><a href="/numbers">Number Resources</a></td> <td class="subsection"> <ul> <li><a href="/abuse">Abuse Information</a></li> </ul> </td> </tr> <tr> <td class="section"><a href="/protocols">Protocols</a></td> <td class="subsection"> <ul> <li><a href="/protocols">Protocol Registries</a></li> <li><a href="/time-zones">Time Zone Database</a></li> </ul> </td> </tr> <tr> <td class="section"><a href="/about">About Us</a></td> <td class="subsection"> <ul> <li><a href="/performance">Performance</a></li> <li><a href="/reports">Reports</a></li> <li><a href="/reviews">Reviews</a></li> <li><a href="/about/excellence">Excellence</a></li> <!-- <li><a href="/news">News</a></li>--> <li><a href="/contact">Contact Us</a></li> </ul> </td> </tr> </table> <div id="custodian"> <p>The IANA functions coordinate the Internet鈥檚 globally unique identifiers, and are provided by <a href="http://pti.icann.org">Public Technical Identifiers</a>, an affiliate of <a href="http://www.icann.org/">ICANN</a>.</p> </div> <div id="legalnotice"> <ul> <li><a href="https://www.icann.org/privacy/policy">Privacy Policy</a></li> <li><a href="https://www.icann.org/privacy/tos">Terms of Service</a></li> </ul> </div> </div> </footer> <script> $(document).ready(function() { $("#nav_dom_idn_sub").hide() $("#nav_dom_root_sub").hide() $("#nav_dom_int_sub").hide() $("#nav_dom_tools_sub").hide() $("#nav_dom_dnssec").addClass("selected") $("#nav_dom_dnssec_ceremonies").addClass("selected") }); </script> </body> </html>