Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
With this commit, the root-anchor provisioning machinery no longer uses g_rootdnsname #5873
g_rootdnsname which might not yet have been initialized when our global scope DNSSEC trust anchor initializing code runs. This broke DNSSEC validation with
I also audited the code for other global scope uses of g_rootdnsname and did not find any, but I did not look too hard.
This minimal fix is super safe for 4.1. A broader fix might be setting a