Bug 1578128
| Summary: | [RFE] Provide delv functionality | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Tom Sorensen <tsorense> |
| Component: | bind | Assignee: | Petr Menšík <pemensik> |
| Status: | CLOSED ERRATA | QA Contact: | Petr Sklenar <psklenar> |
| Severity: | medium | Docs Contact: | Marie Hornickova <mdolezel> |
| Priority: | medium | ||
| Version: | 7.5 | CC: | atragler, ffotorel, mdolezel, mkolaja, pemensik, psklenar, thozza, tsorense |
| Target Milestone: | rc | Keywords: | FutureFeature |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| URL: | https://ftp.isc.org/isc/bind9/cur/9.10/doc/arm/man.delv.html | ||
| Whiteboard: | |||
| Fixed In Version: | bind-9.11.4-1.P2.el7 | Doc Type: | Enhancement |
| Doc Text: |
Feature: A new tool called `delv` (domain entity lookup and validation) has been added. The tools is similar to `dig`, but includes also full DNS Security Extensions (DNSSEC) validation.
Reason: dig +sigchase does not use the same logic as named daemon and is not officially supported. `delv` tool uses exactly the same validation algorithm as `named` daemon.
Result: DNSSEC verification issues are much easier analyzed in a separate tool. Verification against different servers is much simpler now.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-08-06 12:39:40 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1640561 | ||
| Bug Blocks: | 1630905, 1630913, 1663257 | ||
|
Description
Tom Sorensen
2018-05-14 20:37:14 UTC
We have no delv command yet in RHEL 7, but there are some tools that could help with DNSSEC verification failures. Unlike delve, they do not have exactly the same algorithm of names verification as BIND. Most of common DNSSEC errors can be debugged with them easier than dig +sigchase. - drill -S <domain> (from ldns package) - unbound-host -vrD <domain> (from unbound package) I think they are useful alternatives to missing delv, especially the first one. Commit provided in rebase bug, just providing fixed-in version. Note, upstream does not support dig +sigchase anymore, delv is recommended replacement. Failures in +sigchase mode are unsupported by upstream, sigchase support was removed in more recent versions altogether. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2019:2057 |