- 10 May, 2019 1 commit
-
-
Michał Kępień authored
If named is configured to perform DNSSEC validation and also forwards all queries ("forward only;") to validating resolvers, negative trust anchors do not work properly because the CD bit is not set in queries sent to the forwarders. As a result, instead of retrieving bogus DNSSEC material and making validation decisions based on its configuration, named is only receiving SERVFAIL responses to queries for bogus data. Fix by ensuring the CD bit is always set in queries sent to forwarders if the query name is covered by an NTA.
-
- 19 Mar, 2019 1 commit
-
-
Matthijs Mekking authored
More specifically: ignore configured trusted and managed keys that match a disabled algorithm. The behavioral change is that associated responses no longer SERVFAIL, but return insecure.
-
- 10 Dec, 2018 2 commits
-
-
Ondřej Surý authored
-
Ondřej Surý authored
-
- 16 May, 2018 1 commit
-
-
Ondřej Surý authored
-
- 23 Feb, 2018 2 commits
-
-
Ondřej Surý authored
-
Evan Hunt authored
- add CHANGES note - update copyrights and license headers - add -j to the make commands in .gitlab-ci.yml to take advantage of parallelization in the gitlab CI process
-
- 22 Feb, 2018 1 commit
-
-
Evan Hunt authored
-
- 24 Apr, 2017 1 commit
-
-
Evan Hunt authored
-
- 21 Apr, 2017 1 commit
-
-
Mukund Sivaraman authored
-
- 27 Jun, 2016 1 commit
-
-
Mark Andrews authored
-
- 06 Feb, 2015 2 commits
-
-
Tinderbox User authored
-
Evan Hunt authored
4056. [bug] Expanded automatic testing of trust anchor management and fixed several small bugs including a memory leak and a possible loss of key state information. [RT #38458] 4055. [func] "rndc managed-keys" can be used to check status of trust anchors or to force keys to be refreshed, Also, the managed keys data file has easier-to-read comments. [RT #38458]
-
- 07 Jul, 2014 1 commit
-
-
Mark Andrews authored
at start up where not being correctly added to re-signing heaps. [RT #36302]
-
- 18 Jun, 2014 1 commit
-
-
Evan Hunt authored
3882. [func] By default, negative trust anchors will be tested periodically to see whether data below them can be validated, and if so, they will be allowed to expire early. The "rndc nta -force" option overrides this behvaior. The default NTA lifetime and the recheck frequency can be configured by the "nta-lifetime" and "nta-recheck" options. [RT #36146]
-
- 30 May, 2014 1 commit
-
-
Evan Hunt authored
3867. [func] "rndc nta" can now be used to set a temporary negative trust anchor, which disables DNSSEC validation below a specified name for a specified period of time (not exceeding 24 hours). This can be used when validation for a domain is known to be failing due to a configuration error on the part of the domain owner rather than a spoofing attack. [RT #29358]
-
- 07 May, 2014 1 commit
-
-
Evan Hunt authored
3839. [test] Use only posix-compatible shell in system tests. [RT #35625]
-
- 10 Apr, 2014 1 commit
-
-
Evan Hunt authored
3806. [test] Improved system test portability. [RT #35625]
-
- 21 Jan, 2014 2 commits
-
-
Tinderbox User authored
-
Evan Hunt authored
3714. [test] System tests that need to test for cryptography support before running can now use a common "testcrypto.sh" script to do so. [RT #35213]
-
- 05 Sep, 2013 1 commit
-
-
Tinderbox User authored
-
- 04 Sep, 2013 1 commit
-
-
Mark Andrews authored
better. [RT #34625]
-
- 29 Jun, 2012 3 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
-
Tinderbox User authored
-
- 15 Feb, 2011 1 commit
-
-
Mark Andrews authored
3020. [bug] auto-dnssec failed to correctly update the zone when changing the DNSKEY RRset. [RT #23232]
-
- 04 Jan, 2011 1 commit
-
-
Automatic Updater authored
-
- 03 Jan, 2011 1 commit
-
-
Evan Hunt authored
can be switched on by setting "dnssec-validation auto;" in the named.conf options. [RT #21727]
-
- 27 Oct, 2009 1 commit
-
-
Mark Andrews authored
test. [RT #20453]
-
- 02 Mar, 2009 2 commits
-
-
Automatic Updater authored
-
Evan Hunt authored
commands from bin/tests into bin/tools; "make install" will put them in $sbindir. [RT #19301]
-
- 19 Jun, 2007 1 commit
-
-
Automatic Updater authored
-
- 18 Jun, 2007 1 commit
-
-
Automatic Updater authored
-
- 10 Mar, 2004 1 commit
-
-
Mark Andrews authored
[RT #10461]
-
- 05 Mar, 2004 1 commit
-
-
Mark Andrews authored
-
- 09 Jan, 2001 1 commit
-
-
Brian Wellington authored
-
- 08 Aug, 2000 1 commit
-
-
Brian Wellington authored
but it's only for tests. This allows the large files containing random data to be removed from the tree.
-
- 01 Aug, 2000 1 commit
-
-
David Lawrence authored
own CVS tree will help minimize CVS conflicts. Maybe not. Blame Graff for getting me to trim all trailing whitespace.
-
- 27 Jul, 2000 1 commit
-
-
David Lawrence authored
-
- 22 Jun, 2000 1 commit
-
-
David Lawrence authored
-