Fedora Account System
Red Hat Associate
Red Hat Customer
I'm trying to use c-ares to talk the local validating unbound resolver and c-ares doesn't set the AD flag on the query as expected[1]. I'm not aware of any way to configure the library to set AD flag in queries. [1] http://tools.ietf.org/html/rfc6840#section-5.7 Relevant code: https://sourceware.org/git/?p=netresolve.git;a=blob;f=backends/dns.c;hb=HEAD#l404
Created attachment 957376 [details] this patch fixes the issue for me I haven't yet sent the patch upstream, I'm just gathering DNSSEC related bugs in the Fedora bugzilla. I'm working on other DNS and DNSSEC related components, so feel free to reassign the bug report to me.
Please note that Nikos did a lot of work upstream wrt c-ares DNSSEC support. It 'just' needs someone with DNSSEC understanding to review it..
My knowledge of DNSSEC is still improving but I'm willing to give my review where appropriate.
I will handle the upstreaming, assigning to myself until then. Also note that the latest patch to bug #1164337 handles this ticket as well, yet in a different way.
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle. Changing version to '22'. More information and reason for this action is here: https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.