Control: tag -1 confirmed
Christian Hofstaedtler <zeha@debian.org> (2017-07-04):
> pdns-recursor has an embedded copy of the DNS root (".") zone public
> signing key ("KSK"), for DNSSEC verification purposes. ICANN has
> created a new key and expects it to use starting from October 11,
> 2017, in place of the old key.
>
> This update adds the new key to the trusted set. If users do not get
> this update, DNSSEC validation will fail for them starting on Oct.
> 11, until they manually update the configuration.
>
> The same fix is already in unstable (as 4.0.4-2).
Hi Christian,
This looks good to me, feel free to upload.
Are we getting an update for jessie as well? (If so, let's track this in
a separate bug report please.)
Thanks.
KiBi.
Attachment:
signature.asc
Description: Digital signature