- 19 Mar, 2019 1 commit
-
-
Matthijs Mekking authored
More specifically: ignore configured trusted and managed keys that match a disabled algorithm. The behavioral change is that associated responses no longer SERVFAIL, but return insecure.
-
- 15 Mar, 2019 1 commit
-
-
Evan Hunt authored
-
- 25 Jan, 2019 1 commit
-
-
Evan Hunt authored
- work around CR issues - use UTC for time comparisons - use $DIFF instead of cmp
-
- 19 Dec, 2018 1 commit
-
-
Matthijs Mekking authored
dnssec-signzone should sign a zonefile that contains a DNSKEY record with an unsupported algorithm.
-
- 14 Dec, 2018 1 commit
-
-
Mark Andrews authored
-
- 10 Dec, 2018 4 commits
-
-
Ondřej Surý authored
-
Ondřej Surý authored
-
Ondřej Surý authored
-
Mark Andrews authored
-
- 05 Oct, 2018 1 commit
-
-
Ondřej Surý authored
-
- 14 Aug, 2018 1 commit
-
-
Evan Hunt authored
-
- 16 May, 2018 1 commit
-
-
Ondřej Surý authored
-
- 11 May, 2018 1 commit
-
-
Ondřej Surý authored
-
- 23 Feb, 2018 2 commits
-
-
Ondřej Surý authored
-
Evan Hunt authored
- add CHANGES note - update copyrights and license headers - add -j to the make commands in .gitlab-ci.yml to take advantage of parallelization in the gitlab CI process
-
- 22 Feb, 2018 1 commit
-
-
Evan Hunt authored
-
- 13 Dec, 2017 2 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
CDS and CDNSKEY. [RT #46755]
-
- 13 Sep, 2017 1 commit
-
-
Evan Hunt authored
4721. [func] 'dnssec-signzone -x' and 'dnssec-dnskey-kskonly' options now apply to CDNSKEY and DS records as well as DNSKEY. Thanks to Tony Finch. [RT #45689]
-
- 24 Apr, 2017 1 commit
-
-
Evan Hunt authored
-
- 22 Apr, 2017 2 commits
-
-
Tinderbox User authored
-
Mukund Sivaraman authored
-
- 21 Apr, 2017 1 commit
-
-
Mukund Sivaraman authored
-
- 19 Oct, 2016 1 commit
-
-
Witold Krecicki authored
-
- 27 Jun, 2016 1 commit
-
-
Mark Andrews authored
-
- 15 Apr, 2016 1 commit
-
-
Evan Hunt authored
4436. [bug] Fixed a regression introduced in change #4337 which caused signed domains with revoked KSKs to fail validation. [RT #42147]
-
- 10 Mar, 2016 2 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
RRSIG's inception time is in the future and regenerate the RRSIG immediately. [RT #41808]
-
- 28 May, 2015 1 commit
-
-
Tinderbox User authored
-
- 27 May, 2015 1 commit
-
-
Mark Andrews authored
key as per RFC 7344, Section 4.1. [RT #37215]
-
- 30 Oct, 2014 1 commit
-
-
Mark Andrews authored
[RT #37541]
-
- 30 Sep, 2014 1 commit
-
-
Mark Andrews authored
-
- 22 Aug, 2014 2 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
-
- 19 Jun, 2014 1 commit
-
-
Tinderbox User authored
-
- 18 Jun, 2014 1 commit
-
-
Evan Hunt authored
3882. [func] By default, negative trust anchors will be tested periodically to see whether data below them can be validated, and if so, they will be allowed to expire early. The "rndc nta -force" option overrides this behvaior. The default NTA lifetime and the recheck frequency can be configured by the "nta-lifetime" and "nta-recheck" options. [RT #36146]
-
- 07 May, 2014 1 commit
-
-
Evan Hunt authored
3839. [test] Use only posix-compatible shell in system tests. [RT #35625]
-
- 21 Jan, 2014 2 commits
-
-
Tinderbox User authored
-
Evan Hunt authored
3714. [test] System tests that need to test for cryptography support before running can now use a common "testcrypto.sh" script to do so. [RT #35213]
-
- 13 Dec, 2013 1 commit
-
-
Tinderbox User authored
-