mirror of
https://github.com/NLnetLabs/unbound.git
synced 2025-12-20 23:00:56 -05:00
- Fix for zonemd, do not reject insecure result from trust anchor
validation step in dnssec chain of trust.
This commit is contained in:
parent
c802298fca
commit
39a557833d
2 changed files with 3 additions and 1 deletions
|
|
@ -1,5 +1,7 @@
|
|||
23 February 2021: Wouter
|
||||
- Fix for zonemd, that domain-insecure zones work without dnssec.
|
||||
- Fix for zonemd, do not reject insecure result from trust anchor
|
||||
validation step in dnssec chain of trust.
|
||||
|
||||
22 February 2021: Wouter
|
||||
- Fix #431: Squelch permission denied errors for tcp connect
|
||||
|
|
|
|||
|
|
@ -8259,7 +8259,7 @@ void auth_zone_verify_zonemd(struct auth_zone* z, struct module_env* env,
|
|||
dnskey = zonemd_get_dnskey_from_anchor(z, env, mods, anchor,
|
||||
&is_insecure, &why_bogus, &keystorage);
|
||||
lock_basic_unlock(&anchor->lock);
|
||||
if(!dnskey && !reason) {
|
||||
if(!dnskey && !reason && !is_insecure) {
|
||||
reason = "verify DNSKEY RRset with trust anchor failed";
|
||||
}
|
||||
} else if(anchor) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue