[Dnsmasq-discuss] New DNSSEC test release.

Simon Kelley simon at thekelleys.org.uk
Tue Feb 11 13:42:12 GMT 2014


On 11/02/14 12:10, Jan-Piet Mens wrote:
>> One thing to note: I've also completely changed the way the trust
>> anchors are specified, from DNSKEYS to DS records.
>
> Very nice and, yes, it works. :)
>
> All that's left

I wish, I wish. NSEC3 is still lurking.

> is to find a way to obtain those securely when dnsmasq
> starts up, somewhat in the way unbound-anchor(1) from Unbound does.

Is unbound-anchor fairly stand-alone? Maybe run unbound-anchor and then 
covert the format of the resulting trust-anchors file would be a viable 
solution?



Simon.


>
>          -JP
>
> _______________________________________________
> Dnsmasq-discuss mailing list
> Dnsmasq-discuss at lists.thekelleys.org.uk
> http://lists.thekelleys.org.uk/mailman/listinfo/dnsmasq-discuss
>




More information about the Dnsmasq-discuss mailing list