[Opendnssec-develop] Re: [OpenDNSSEC] #217: KASP accepts algorithm 2 for NSEC3 records

Matthijs Mekking matthijs at NLnetLabs.nl
Tue Feb 15 09:09:22 UTC 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Could you say why it is eek?

On 02/15/2011 09:20 AM, Alex Dalitz wrote:
>> Yes, ods-kaspcheck validated the policy. Alex has committed a fix in trunk
>> (rev 4433) that fixes this.
>>
>> The signer bug is fixed in ldns, but that doesn't help OpenDNSSEC for now
>> of course. We decided to fix the enforcer such that it will make sure not
>> to accept policies that are not validated by ods-kaspcheck.
> 
> 
> Eek!
> 
> Has anybody tested this?
> 
> Thanks,
> 
> 
> Alex.
> _______________________________________________
> Opendnssec-develop mailing list
> Opendnssec-develop at lists.opendnssec.org
> https://lists.opendnssec.org/mailman/listinfo/opendnssec-develop
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJNWkLCAAoJEA8yVCPsQCW51fgH/jOLP9m9PtULtXy1BR44qy42
q01csZfnnSu71zafRsCkTw0PmvN9DZ1Ynkk8BQKKmS02cHPkPH8i38zFyRg13Ro6
GjfRDCTXpbwjttVtwTP6tMXslwuEpbrS2wlA08rgatWX/LxRWwdgOMneWQJpv5M2
PivFWbC+s2lwyB8EaN+avbHTPOtsoHS62TEKz5dbZPi/mAJzNPMC8P8aCkrCbiww
GD1vE5GYciU1vDKZzo/nqNdIPd606y8QOtN2FElfdx/SYMVXZtuOCXcHn8UzHCxm
bUON5UvxxqVxquefqn2vI8qq6jjM2bfUwuVlg239b6zYuiID5g8F1uZWweXGNHk=
=mMCO
-----END PGP SIGNATURE-----



More information about the Opendnssec-develop mailing list