[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: BIND 9 DNSSEC Validation Fails on new DS record



[X-Debbugs-Cc makes things much easier... ;p]

On Mon, 2011-02-07 at 12:44 +0000, Ben Hutchings wrote:
> <https://www.isc.org/announcement/bind-9-dnssec-validation-fails-new-ds-record>.
> 
> "When a DS record for .COM is inserted into the root on 31 March 2011,
> non-upgraded BIND 9 resolvers with DNSSEC validation enabled will have a
> high probability of being unable to successfully resolve .COM names unless
> they are restarted."
> 
> Probably merits an update in oldstable update 5.0.9.

With my SRM hat on, I'd certainly be interested in seeing what a diff to
fix this in lenny looks like.

Regards,

Adam


Reply to: