DNSSEC: Key sizes among TLDs, fresh survey
Jay asked me to share the following numbers with the community. Currently the root zone has 310 TLDs (according to the list posted at http://data.iana.org/TLD/tlds-alpha-by-domain.txt). 75 TLDs have their zone signed, representing 24.2% of the total. By querying one of the authoritative nameservers for each TLD, asking for the DNSKEY, we identified the key length for the KSK and ZSK. The current state of things are: KSK size Count TLDs 1024 3 CH, KG, LI 1280 2 BR, GR 2048 67 4096 2 BG, NA ---- 74 ZSK size Count TLDs 1024 73 1152 1 BR 2048 1 GOV ----- 75 The difference between KSK and ZSK count is explained by one TLD (NU), who are using what is called a CSK (Common Signing Key). Cheers, -- Sebastian Castro DNS Specialist .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 495 2337 mobile: +64 21 400535
nary a prime in sight! (and more interesting, is there any algo diversity?) /bill On Fri, Jun 10, 2011 at 12:13:42PM +1200, Sebastian Castro wrote:
Jay asked me to share the following numbers with the community.
Currently the root zone has 310 TLDs (according to the list posted at http://data.iana.org/TLD/tlds-alpha-by-domain.txt).
75 TLDs have their zone signed, representing 24.2% of the total.
By querying one of the authoritative nameservers for each TLD, asking for the DNSKEY, we identified the key length for the KSK and ZSK.
The current state of things are:
KSK size Count TLDs 1024 3 CH, KG, LI 1280 2 BR, GR 2048 67 4096 2 BG, NA ---- 74
ZSK size Count TLDs 1024 73 1152 1 BR 2048 1 GOV ----- 75
The difference between KSK and ZSK count is explained by one TLD (NU), who are using what is called a CSK (Common Signing Key).
Cheers, -- Sebastian Castro DNS Specialist .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 495 2337 mobile: +64 21 400535 _______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
participants (2)
-
bmanning@vacation.karoshi.com
-
Sebastian Castro