Key Management

The current DNSSEC keys for the top level domains .ch and .li are published here for name server operators.

NB: The keys for the top level domains .ch and .li should not be directly configured as trust anchors in your name servers. Instead, you should make sole use of the root-zone keys. Our keys are only set out here for checking purposes.

Current DNSSEC keys

CH: Key 30010, intended validity until 31 December 2016
DS 30010 8 1 6C987A562D76215ADA6FA9D8B21E5EF5F7D2BA49
DS 30010 8 2 53EC0B45A417CBA93884BD1D2D22249274A6424BDD2CF9CAE55A0B09F73DEE54

LI: Key 10600, intended validity until 31 December 2016
DS 10600 8 1 8862B0256FB199991A445D5C02664D188AFF4A66
DS 10600 8 2 517A05281B5B392207920DB42D9AE352B6498C09B4494381C006C3727F6A4081

Key Management Practice Statement

The "Key Management Practice Statement" document describes how SWITCH handles the cryptographic key material associated with DNSSEC. It explains how the keys are generated and saved and when they lose their validity.

Key Management Practice StatementPDF