- Fix for zonemd, do not reject insecure result from trust anchor

validation step in dnssec chain of trust.
This commit is contained in:
W.C.A. Wijngaards 2021-02-23 17:09:40 +01:00
parent c802298fca
commit 39a557833d
2 changed files with 3 additions and 1 deletions

View file

@ -1,5 +1,7 @@
23 February 2021: Wouter
- Fix for zonemd, that domain-insecure zones work without dnssec.
- Fix for zonemd, do not reject insecure result from trust anchor
validation step in dnssec chain of trust.
22 February 2021: Wouter
- Fix #431: Squelch permission denied errors for tcp connect

View file

@ -8259,7 +8259,7 @@ void auth_zone_verify_zonemd(struct auth_zone* z, struct module_env* env,
dnskey = zonemd_get_dnskey_from_anchor(z, env, mods, anchor,
&is_insecure, &why_bogus, &keystorage);
lock_basic_unlock(&anchor->lock);
if(!dnskey && !reason) {
if(!dnskey && !reason && !is_insecure) {
reason = "verify DNSKEY RRset with trust anchor failed";
}
} else if(anchor) {