Skip to content
  • Evan Hunt's avatar
    [master] tag initializing keys so they can't be used for normal validation · 560d8b83
    Evan Hunt authored
    4773.	[bug]		Keys specified in "managed-keys" statements
    			can now only be used when validating key refresh
    			queries during initialization of RFC 5011 key
    			maintenance. If initialization fails, DNSSEC
    			validation of normal queries will also fail.
    			Previously, validation of normal queries could
    			succeed using the initializing key, potentially
    			masking problems with managed-keys. [RT #46077]
    560d8b83