public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* RSA/SHA1-NSEC3-SHA1 signature bug?
@ 2014-10-21 13:11 Michael Tremer
  2014-10-22  2:50 ` R. W. Rodolico
  2014-10-22  5:58 ` R. W. Rodolico
  0 siblings, 2 replies; 4+ messages in thread
From: Michael Tremer @ 2014-10-21 13:11 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 544 bytes --]

Hello fellow dnsmasq users,

there is a topic on the IPFire support forums I would like to point you
to:

  http://forum.ipfire.org/index.php?topic=11726.0

It appears that dnsmasq cannot verify resource records of a
DNSSEC-enabled domain. That domain uses RSA/SHA1-NSEC3-SHA1 for its
signatures. Although there is some code in dnsmasq that is supposed to
handle this, it does not verify the records correctly.

Did anyone else experience this problem? Is it a bug with dnsmasq or the
authoritative name servers of that domain?

Best,
-Michael

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 819 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2014-10-22 12:01 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-10-21 13:11 RSA/SHA1-NSEC3-SHA1 signature bug? Michael Tremer
2014-10-22  2:50 ` R. W. Rodolico
2014-10-22  5:58 ` R. W. Rodolico
2014-10-22 12:01   ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox