Reply to post: Re: How long before things would stop working properly?

Internet's safe-keepers forced to postpone crucial DNSSEC root key signing ceremony – no, not a hacker attack, but because they can't open a safe

Anonymous Coward
Anonymous Coward

Re: How long before things would stop working properly?

"I'm surprised there isn't at least a third safe!"

There is. A HSM sits in a secure warehouse somewhere, containing an encrypted copy of the KSK with "Recovery Key Share Holders" around the world possessing smartcards (shards) to decrypt it.

If both key management facilities fall into the ocean, 5-of-7 RKSH smartcards and an encrypted KSK smartcard can reconstitute KSK in a new HSM.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon