Trust anchors
A validating resolver starts from this key: the key that signs the DNSKEY set of the GOpenCDR root.
Root KSK 46714
Algorithm 13, published 28 September 2026DS
. IN DS 46714 13 2 1519B9AC6BF0DB14F467EB33E46384AE170EFA9D66660D5B01C141049592B89CDNSKEY
root-anchors.xmlroot-anchors.jsonSignature. IN DNSKEY 257 3 13 qXdp/XtrE70h5TPf26nvTSW8db6hVd4VFAicBWLYgn7PvKlY+Nk5lUrioM7bqUQbuISbqep5xdDuvzZnHn8/rg==Check it yourself
The same key is on this page, in transparency log entry 21, and in the root zone itself. With BIND's tools, from any computer:
dig @ns1.cdr.gplatform.org . DNSKEY +noall +answer | dnssec-dsfromkey -f - .Expected output
. IN DS 46714 13 2 1519B9AC6BF0DB14F467EB33E46384AE170EFA9D66660D5B01C141049592B89C
The files are signed with the anchor bundle key cdr.gplatform.org/anchors+128b735b+AT1Opgaqy4oVJDHakR6OlSVHxZcOpD3Xe/Kh9NAs88Jt. They name the transparency log cdr.gplatform.org/tlog, whose checkpoints are signed with cdr.gplatform.org/tlog+4fa558fc+AYRwZ0KSEaaWcNsS6rExAM3aGE4Ru5wIqtRxReRWnptA.
Rollover schedule
None scheduled. The root KSK rolls every two years under the timers of RFC 5011, the first time within 12 months of launch, as P-2 sets out.