Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dig tool not compile with -DDIG_SIGCHASE , so no dnssec validation #10728

Closed
hugdru opened this issue Oct 30, 2015 · 4 comments
Closed

dig tool not compile with -DDIG_SIGCHASE , so no dnssec validation #10728

hugdru opened this issue Oct 30, 2015 · 4 comments

Comments

@hugdru
Copy link

hugdru commented Oct 30, 2015

Because, https://github.com/NixOS/nixpkgs/blob/master/pkgs/servers/dns/bind/default.nix , is not compiled with STD_CDEFINES="-DDIG_SIGCHASE=1"; export STD_CDEFINES . I cannot chase DNSSEC signature chains.

README - https://bazaar.launchpad.net/~ubuntu-branches/ubuntu/vivid/bind9/vivid/view/head:/README#L184
Same bug - https://bugs.launchpad.net/ubuntu/+source/bind9/+bug/257682
Other Info - http://www.crypt.gen.nz/papers/dns_security_2.html

@copumpkin
Copy link
Member

Is it as simple as adding the flag? Or are there other gotchas that explain why it's not on by default?

@hugdru
Copy link
Author

hugdru commented Oct 30, 2015

I have no idea. But from the bind readme and the dig --help it seems it is as easy as adding that flag. I am new to nixos so I don't yet know how to write packages, etc. So I can test on my machine.

@Profpatsch
Copy link
Member

Profpatsch commented Jul 23, 2016

(triage) status?

FlorentBecker added a commit to FlorentBecker/nixpkgs that referenced this issue Feb 19, 2017
@FlorentBecker
Copy link
Contributor

@hugdru, can you test the above pull request?

@vcunat vcunat closed this as completed in f1e7a60 Feb 19, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants