[Pkg-dns-devel] Bug#866112: Bug#866112: pdns-recursor: Embedded "root" DNSSEC Trust Anchor will expire in 2017

Ondřej Surý ondrej at sury.org
Tue Jun 27 13:20:56 UTC 2017


Actually it would be best if you could convince pdns_recursor to use TAs 
from dns-root-data, either at build or preferably at start time (or runtime).

Ondřej


On 27 June 2017 14:33:12 Christian Hofstaedtler <zeha at debian.org> wrote:

> Package: pdns-recursor
> Version: 4.0.4-1
> Severity: important
> Tags: upstream fixed-upstream
>
> pdns-recursor embeds the "root" DNSSEC Trust Anchor in its source code,
> and the currently in use KSK-2010 will soon be replaced by KSK-2017. The
> former is embedded, the latter is not.
>
> Upstream has fixed this already:
> https://github.com/PowerDNS/pdns/commit/d5037c4d34ffbc89ca5d4f79554dd87aa49fdbc8
>
> _______________________________________________
> pkg-dns-devel mailing list
> pkg-dns-devel at lists.alioth.debian.org
> https://lists.alioth.debian.org/mailman/listinfo/pkg-dns-devel



More information about the pkg-dns-devel mailing list