mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-09-12 04:47:41 +02:00
- Fix for zonemd, do not reject insecure result from trust anchor
validation step in dnssec chain of trust.
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
23 February 2021: Wouter
|
||||
- Fix for zonemd, that domain-insecure zones work without dnssec.
|
||||
- Fix for zonemd, do not reject insecure result from trust anchor
|
||||
validation step in dnssec chain of trust.
|
||||
|
||||
22 February 2021: Wouter
|
||||
- Fix #431: Squelch permission denied errors for tcp connect
|
||||
|
||||
+1
-1
@@ -8259,7 +8259,7 @@ void auth_zone_verify_zonemd(struct auth_zone* z, struct module_env* env,
|
||||
dnskey = zonemd_get_dnskey_from_anchor(z, env, mods, anchor,
|
||||
&is_insecure, &why_bogus, &keystorage);
|
||||
lock_basic_unlock(&anchor->lock);
|
||||
if(!dnskey && !reason) {
|
||||
if(!dnskey && !reason && !is_insecure) {
|
||||
reason = "verify DNSKEY RRset with trust anchor failed";
|
||||
}
|
||||
} else if(anchor) {
|
||||
|
||||
Reference in New Issue
Block a user