Skip to content

Present "resolving error for DANE TLSA record" in stead of "no DANE TLSA record" (false negative) #681

Description

@baknu

From a mail conversation between BK and GT (subject: "Comparison between dev.internet.nl and internet.nl" / date: 9 February 2022):

Besides I found the following inconsistency that is a possible false negative in our measurements. Sometimes we do not detect a DANE record that should be there. This happens on all environments. I thought that this would not be possible with DNSSEC signed domains and a validating resolver on the side of Internet.nl. George might be able to tell what is happening here.

You are right. No data and DNSSEC should result to bogus.
I believe here Unbound is returning SERVFAIL (something wrong with
resolving; probably no answer or something else).
I think we need to check the SERVFAIL RCODE and present something
different like resolution error instead of no TLSA record.

Tip: the rcode here
(

data["rcode"] = result.rcode
)
can go before the if and checked at the dane logic.

Metadata

Metadata

Assignees

Labels

bugUnexpected or unwanted behaviour of current implementations

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions