Bug 2120605 - [Tracker] dnssec issues on fedora37
Summary: [Tracker] dnssec issues on fedora37
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: 37
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Florence Blanc-Renaud
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On: 2115865 2117342 2117859
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-08-23 11:32 UTC by Florence Blanc-Renaud
Modified: 2023-02-07 16:22 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-02-07 16:22:02 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-8680 0 None None None 2022-08-23 11:37:57 UTC

Description Florence Blanc-Renaud 2022-08-23 11:32:57 UTC
This BZ is a tracker for dnssec-related issues on fedora 37.

Currently we are seeing 2 different types of failures:
- on an IPA server with dnssec-validation enabled, openQA detects a failure enrolling freeipa client because of DNS issues (the DNS resolution fails for kojipkgs.fedoraproject.org)
- on an IPA server with DNSSEC enabled, enabling zone signing for a given zone does not create the DNSKEY records and the zone is not signed.


Relevant BZ: 
#2117859 -  FreeIPA client enrolment fails due to DNS issues with openssl-pkcs11-0.4.12-2.fc37 on server
#2117342 - dnssec-keyfromlabel fails with fatal: failed to get key dnssec.test/RSASHA256: no engine
#2115865 - dnssec-keyfromlabel fails with openssl-pkcs11-0.4.12-1.fc36

When the above BZs are fixed, freeipa will need to bump its "Requires:" for bind and openssl-pkcs11 packages.

Comment 1 Florence Blanc-Renaud 2022-11-22 08:08:19 UTC
FreeIPA spec file has bumped the required bump version:

master:
    dface55 Spec file: bump bind version on f37+

ipa-4-10:
    1dfb5d5 Spec file: bump bind version on f37+

Comment 2 Florence Blanc-Renaud 2023-02-07 16:22:02 UTC
The 3 bugs tracked by this BZ have been closed as fixed, hence I'm also closing this one.


Note You need to log in before you can comment on or make changes to this bug.