[Dnsmasq-discuss] DNSSEC validation
Chris Staite
chris at yourdreamnet.co.uk
Tue Apr 12 23:58:38 UTC 2022
Hi,
I’ve noticed that the 1.1.1.1/help was not working when running through dnsmasq.
It appears there’s a bug in the logic when a CNAME is returned from an unsigned zone. I think there’s another bug in there in general that it returns BOGUS when a zone is SECURE also?
Anyway, please see my attached patch which remedies my problem and I believe implements DNSSEC as it was intended.
Thanks, Chris.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: dnssec.patch
Type: application/octet-stream
Size: 834 bytes
Desc: not available
URL: <http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/attachments/20220413/34a2335b/attachment.obj>
More information about the Dnsmasq-discuss
mailing list