ARIN Deploys DNSSEC Zone Signing
Posted: 01 July 2009
On 1 July 2009 ARIN will begin phase two of its DNSSEC project by publishing the zones that it is authoritative for under in-addr.arpa.
Because the parent zone (in-addr.arpa) is not signed, you will need to place the advertised keys as part of your DNS server configuration as defined on ARIN's trust anchor list. The list is available for download in BIND-style and zone-file format at:
The DNSSEC project will be completed in three phases. The third and final phase is allowing DS records from ARIN-issued delegations that have secured zones. View the detailed deployment plan at:
To learn more about DNSSEC, please look at http://www.dnssec.net/.
Chief Technology Officer
American Registry for Internet Numbers (ARIN)
These are archives of announcements, and have generally not been updated since they were published. As a result, some content, specifically links to other pages and other references may be out-of-date or no longer available.