Project

General

Profile

Enhancement #292

DNSSEC authoritative nameservers and validating resolvers should be separated

Added by Marc Dequènes about 7 years ago. Updated almost 2 years ago.

Status:
Blocked
Priority:
Low
Category:
Service :: DNS
Start date:
2012-02-13
Due date:
% Done:

0%

Patch Available:
No
Confirmed:
No
Branch:
Entity:
DuckCorp
Security:
No
Help Needed:
Yes

Description

According to RFC4035 3.1.6 (The AD and CD Bits in an Authoritative Response), it is normal behavior an authoritative nameserver returns AA without AD flag. In bind9 there is no way to either consider authoritative zones data to be authentic « without further validation », or redo validation (which would be silly while serving the zone outside).

Considered solutions:
  • on DNS servers: try to use a bind9 view for localhost request, which would not share any zone but act as a recursive validating resolver if possible, or use unbound as validating resolver (in resolv.conf only)
  • on other servers: use unbound as validating resolver

Related issues

Blocked by DuckCorp Infrastructure - Enhancement #287: 42 DNS Rejected 2012-02-03

History

#1 Updated by Marc Dequènes about 7 years ago

Maybe having unbound listen on 127.0.0.1, have resolv.conf use it, and bind9 servers always listen only on external IPs would be a simpler and an easier to maintain configuration (i'm less and less thinking a view could help because it still has to revolve which probably will become an impossible request loop).

#2 Updated by Marc Dequènes about 7 years ago

  • Status changed from New to In Progress

On machines using DHCP, using unbound and resolconf should be fine.

#3 Updated by Marc Dequènes over 6 years ago

  • Priority changed from High to Normal

#4 Updated by Marc Dequènes about 5 years ago

  • Tracker changed from Bug to Enhancement
  • Priority changed from Normal to Low

#5 Updated by Marc Dequènes almost 4 years ago

  • Help Needed changed from No to Yes

#6 Updated by Marc Dequènes almost 4 years ago

#7 Updated by Marc Dequènes almost 2 years ago

  • Status changed from In Progress to Blocked

Also available in: Atom PDF