We kindly inform that NASK began to institute DNSSEC on the .pl Registry production server. The process was divided into stages.
First stage consists of signing domain names maintained by NASK and making them accessible on public .pl domain servers. This operation is planned to be conducted on the 20th of December 2011. During this time we will observe stability of the new service and if any problems do occur, NASK may switch the service off for some time. Until this stage is complete, NASK does not recommend to switch on the DNSSEC validation for .pl, functional (ex: com.pl, net.pl) and regional (ex: waw.pl, wroclaw.pl) domains for any other reason than testing purposes.
First stage of the institution will end with placing the .pl domain DS record in the root zone. We plan to make this happen on the break of January and February 2012. From that moment the DNSSEC validation for domains, maintained by NASK, may be switched on. We recommend to switch on the validation in respect to the root zone main key.
Last stage of the institution will be to make it possible to secure names, registered in .pl, functional and regional domains, maintained by NASK. We plan to do it in the second quarter of 2012.
After the institution of DNSSEC is complete, it will be possible to verify the authenticity and integrity of responses, received from name servers which are secured by this protocol.