On 11 jun 2010, at 11.13, Antoin Verschuren wrote: > SO what's the use of the ICANN key ceremony then, when OpenDNSSEC can do an unattended KSK key rollover at will ? ICANN uses OpenDNSSEC for the GSI (Generic Signing Infrastructure[1]), but not for the Root Zone Key Management. jakob [1] http://dns.icann.org/services/gsi/