[Dnsmasq-discuss] DNSSEC validation

Chris Staite chris at yourdreamnet.co.uk
Tue Apr 12 23:58:38 UTC 2022


Hi,

I’ve noticed that the 1.1.1.1/help was not working when running through dnsmasq.

It appears there’s a bug in the logic when a CNAME is returned from an unsigned zone.  I think there’s another bug in there in general that it returns BOGUS when a zone is SECURE also?

Anyway, please see my attached patch which remedies my problem and I believe implements DNSSEC as it was intended.

Thanks, Chris.


-------------- next part --------------
A non-text attachment was scrubbed...
Name: dnssec.patch
Type: application/octet-stream
Size: 834 bytes
Desc: not available
URL: <http://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/attachments/20220413/34a2335b/attachment.obj>


More information about the Dnsmasq-discuss mailing list