NordVPN Promotion

Home / News

DNSSEC Validation Climbs Across Africa Ahead of Root Key Rollover

DNSSEC validation in Africa has risen sharply over the past five years, with ICANN reporting that 53% of users on the continent are now behind resolvers capable of validating DNSSEC, an increase of more than 140%. The gains come weeks before the DNS root’s next Key Signing Key rollover on October 11.

Independent measurements broadly support ICANN’s country-level figures. ICANN’s September 24 analysis of DNS security deployments in Africa and the Middle East puts Ghana’s validation rate at about 98%, up from roughly 20%, and says Nigeria is approaching 60%. APNIC Labs’ separate measurements for the 30 days through September 20 put full DNSSEC validation at 99.15% in Ghana and 60.49% in Nigeria. Its corresponding figure for Africa was 55.09%, somewhat above ICANN’s 53%.

The measurements are not necessarily directly interchangeable: DNSSEC validation statistics depend on measurement methodology and on how partial validation is treated. APNIC, for example, separately reports users for whom its tests produce mixed validation results. Including that category raises its measured African total substantially. :chatgpt-content-reference{index="3"}

Resolver validation and signing a country’s namespace are separate parts of DNSSEC deployment. ICANN attributed much of Ghana’s increase to MTN Ghana enabling validation across its resolver infrastructure. Yet IANA’s current delegation data for the .gh country-code top-level domain does not publish a DS record, meaning the ccTLD itself does not currently establish a DNSSEC chain of trust from the root. Nigeria has moved on both fronts: ICANN says MTN Nigeria’s resolver deployment contributed to its rising validation rate, while the Nigeria Internet Registration Association has signed .ng; IANA’s delegation record now includes a DS record for the domain.

Elsewhere in the region, deployment remains uneven. ICANN says work with Jordan’s financial-sector regulator has renewed efforts to sign .jo, whose current IANA delegation record likewise contains no DS record.

The immediate operational test arrives October 11. On that date, the successor root KSK, KSK-2024, is scheduled to begin signing the root zone and the current key will stop doing so. ICANN is urging operators of validating resolvers to verify that KSK-2024, key tag 38696, is installed as a trust anchor rather than assuming automatic updates succeeded. A validating resolver that has not acquired the new trust anchor could fail DNSSEC validation after the rollover.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By CircleID Reporter —

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

DNS

Sponsored byDNIB.com

New TLDs

Sponsored byRadix

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

Brand Protection

Sponsored byCSC

NordVPN Promotion