|
||
DNSSEC validation in Africa has risen sharply over the past five years, with ICANN reporting that 53% of users on the continent are now behind resolvers capable of validating DNSSEC, an increase of more than 140%. The gains come weeks before the DNS root’s next Key Signing Key rollover on October 11.
Independent measurements broadly support ICANN’s country-level figures. ICANN’s September 24 analysis of DNS security deployments in Africa and the Middle East puts Ghana’s validation rate at about 98%, up from roughly 20%, and says Nigeria is approaching 60%. APNIC Labs’ separate measurements for the 30 days through September 20 put full DNSSEC validation at 99.15% in Ghana and 60.49% in Nigeria. Its corresponding figure for Africa was 55.09%, somewhat above ICANN’s 53%.
The measurements are not necessarily directly interchangeable: DNSSEC validation statistics depend on measurement methodology and on how partial validation is treated. APNIC, for example, separately reports users for whom its tests produce mixed validation results. Including that category raises its measured African total substantially. :chatgpt-content-reference{index="3"}
Resolver validation and signing a country’s namespace are separate parts of DNSSEC deployment. ICANN attributed much of Ghana’s increase to MTN Ghana enabling validation across its resolver infrastructure. Yet IANA’s current delegation data for the .gh country-code top-level domain does not publish a DS record, meaning the ccTLD itself does not currently establish a DNSSEC chain of trust from the root. Nigeria has moved on both fronts: ICANN says MTN Nigeria’s resolver deployment contributed to its rising validation rate, while the Nigeria Internet Registration Association has signed .ng; IANA’s delegation record now includes a DS record for the domain.
Elsewhere in the region, deployment remains uneven. ICANN says work with Jordan’s financial-sector regulator has renewed efforts to sign .jo, whose current IANA delegation record likewise contains no DS record.
The immediate operational test arrives October 11. On that date, the successor root KSK, KSK-2024, is scheduled to begin signing the root zone and the current key will stop doing so. ICANN is urging operators of validating resolvers to verify that KSK-2024, key tag 38696, is installed as a trust anchor rather than assuming automatic updates succeeded. A validating resolver that has not acquired the new trust anchor could fail DNSSEC validation after the rollover.
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byDNIB.com
Sponsored byRadix
Sponsored byVerisign
Sponsored byVerisign
Sponsored byCSC