[Opendnssec-user] OpenDNSSEC vs. BIND 9.20.29?
Havard Eidnes
he at uninett.no
Fri Sep 18 12:55:28 UTC 2026
Hi,
it appears that one of the security fixes in the BIND 9.20.29
release is hitting a possible bug of omission in OpenDNSSEC, at
least in version 2.1.13 (no, I'm not on the latest...), ref.:
Require a TSIG on every message of incoming zone
transfers. (CVE-2026-19033)
Previously, named accepted TSIG-signed zone transfers in
which some messages were unsigned, and processed those
messages before the next signature could vouch for them. It
now requires a TSIG on every message of an incoming AXFR or
IXFR; all modern nameservers already sign every message, so
no change is expected in practice. [GL #6062]
After upgrading the "downstream" name server of OpenDNSSEC to
BIND 9.20.29, I'm seeing
Sep 18 14:26:33 xxxxx ods-signerd: [socket] unable to handle outgoing tcp response: write() failed (Broken pipe)
messages logged by OpenDNSSEC, and on the BIND side:
Sep 18 12:05:21 yyyyy named[22162]: 0x6fe6d25cec10: transfer of '114.39.158.in-addr.arpa/IN' from a.b.c.d#53: failed while receiving responses: expected a TSIG or SIG(0)
(No, those are not the same event, but the pattern is clear.)
For now I'm downgrading the downstream BIND name server to the
previous BIND release, 9.20.27 (28 was skipped).
It would however be nice if this bug of omission in OpenDNSSEC
could be fixed. Any chance of that happening?
Best regards,
- Håvard
More information about the Opendnssec-user
mailing list