New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

rec: Fix erroneous check for section 4.1 of rfc6840 #5670

Merged
merged 3 commits into from Sep 13, 2017

Conversation

Projects
None yet
3 participants
@rgacogne
Member

rgacogne commented Sep 6, 2017

Short description

The DNSSEC validation check for section 4.1 of rfc6840 was wrong, leading to a Bogus validation state when getting a denial from the root zone.
Also fixes a bug in a DNSSEC validation corner case with forwarded zones, uncovered by this fix (we should go Bogus if we get an NXDomain answer from the parent when trying to get a DS record for a name we were told exists, by the authoritative server we forwarded to).

Fixes #5648.
Supersedes #5651.

Checklist

I have:

  • read the CONTRIBUTING.md document
  • compiled and tested this code
  • included documentation (including possible behaviour changes)
  • documented the code
  • added or modified regression test(s)
  • added or modified unit test(s)

@rgacogne rgacogne added this to the rec-4.1.0 milestone Sep 6, 2017

@aerique aerique requested a review from Habbie Sep 11, 2017

@Habbie Habbie referenced this pull request Sep 12, 2017

Closed

[WIP] fix root zone denials #5651

1 of 7 tasks complete
@Habbie

Works. Will review code later today.

@Habbie

Habbie approved these changes Sep 12, 2017

One question, but I think this looks good.

Show outdated Hide outdated pdns/validate.cc Outdated
@Habbie

This comment has been minimized.

Show comment
Hide comment
@Habbie

Habbie Sep 12, 2017

Member
Member

Habbie commented Sep 12, 2017

rgacogne added some commits Sep 5, 2017

@aerique aerique merged commit 49ed380 into PowerDNS:master Sep 13, 2017

1 check passed

continuous-integration/travis-ci/pr The Travis CI build passed
Details

@rgacogne rgacogne deleted the rgacogne:rec-5648-root-denial branch Sep 13, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment