BIND 9 DNSSEC Validation Fails on new DS record
Package: bind9
Version: 1:9.6.ESV.R3+dfsg-0+lenny1
Severity: important
This is described in
<https://www.isc.org/announcement/bind-9-dnssec-validation-fails-new-ds-record>.
"When a DS record for .COM is inserted into the root on 31 March 2011,
non-upgraded BIND 9 resolvers with DNSSEC validation enabled will have a
high probability of being unable to successfully resolve .COM names unless
they are restarted."
Probably merits an update in oldstable update 5.0.9.
Ben.
Reply to: