The DNSSEC KSK of the root rolls.
The DNSSEC key signing key (or KSK) of the DNS root zone will be changed (rolled) this summer 2017. During the time between July and October, all DNSSEC validating resolver need to get the new key material.
In an ideal world, everything works automagically.
In this webinar we explain the KSK roll, how DNS resolver will load the new KSK with the RFC 5011 protocol and how a DNS administrator can verify that the new KSK is present in the resolvers configuration.