Bug 1096240 - info: validation failure repos.fedorapeople.org
Summary: info: validation failure repos.fedorapeople.org
Keywords:
Status: CLOSED DUPLICATE of bug 824219
Alias: None
Product: Fedora
Classification: Fedora
Component: dnssec-trigger
Version: 20
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Paul Wouters
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-05-09 14:05 UTC by Hedayat Vatankhah
Modified: 2014-10-30 15:06 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-10-30 15:06:30 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Hedayat Vatankhah 2014-05-09 14:05:23 UTC
Description of problem:
Doesn't validate repos.fedorapeople.org

Version-Release number of selected component (if applicable):
unbound-1.4.21-3.fc20.x86_64

Comment 1 Paul Wouters 2014-05-09 15:21:48 UTC
That does not seem to exist, so why do you think it should validate?

$ dig any repos.fedoraproject.org @ns-sb01.fedoraproject.org.

; <<>> DiG 9.9.3-rl.13207.22-P2-RedHat-9.9.3-15.P2.fc19 <<>> any repos.fedoraproject.org @ns-sb01.fedoraproject.org.
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 31450
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;repos.fedoraproject.org.	IN	ANY

;; AUTHORITY SECTION:
fedoraproject.org.	300	IN	SOA	ns04.fedoraproject.org. hostmaster.fedoraproject.org. 1110035712 3600 600 2419200 86400

;; Query time: 50 msec
;; SERVER: 69.174.247.243#53(69.174.247.243)
;; WHEN: Fri May 09 11:21:14 EDT 2014
;; MSG SIZE  rcvd: 104

Comment 2 Paul Wouters 2014-05-09 15:23:47 UTC
ohh. people..... you are mostl likely behind a broken bind forwarder with the cname/wildcard DNSSEC bug. you can check with sudo unbound-control list_forwards

Comment 3 Paul Wouters 2014-05-09 15:29:43 UTC
See rhbz#id=824219

Comment 4 Paul Wouters 2014-05-13 18:07:31 UTC
we now have some records we can use to test for this scenario in dnssec-trigger

*._probe.us.com IN CNAME fedoraproject.org.
*._probe.uk.com IN CNAME fedoraproject.org.
*._probe.kr.com IN CNAME fedoraproject.org.
*._probe.uk.net IN CNAME fedoraproject.org.

Next is to extend the dnssec-triggerd dnssec tests to test for this bug

Comment 5 Pavel Šimerda (pavlix) 2014-09-23 09:52:39 UTC
Related to https://bugzilla.redhat.com/show_bug.cgi?id=824219 ?

Comment 6 Pavel Šimerda (pavlix) 2014-10-30 15:06:30 UTC

*** This bug has been marked as a duplicate of bug 824219 ***


Note You need to log in before you can comment on or make changes to this bug.