Bug 491655
| Summary: | bind doesn't handle unknown DLV algorithms well | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | Adam Tkac <atkac> |
| Component: | bind | Assignee: | Adam Tkac <atkac> |
| Status: | CLOSED ERRATA | QA Contact: | BaseOS QE <qe-baseos-auto> |
| Severity: | high | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 5.3 | CC: | bill, derekmorr, dkovalsk, jason.redhat.20030417, jplans, msusta, ovasik, rvokal |
| Target Milestone: | rc | Keywords: | ZStream |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2009-09-02 07:36:46 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 504794 | ||
|
Description
Adam Tkac
2009-03-23 14:17:49 UTC
For example, not being able to resolve the .gov domain if DNSSEC is enabled is a problem for many users with their new signing algorithm in use that seemed to be triggered late this week. Even Fedora, running 9.5.1-2.p2 requires dnssec-validate no to resolve .gov domains and trying to import the public key for .gov yields an invalid algorithm message. (In reply to comment #5) > For example, not being able to resolve the .gov domain if DNSSEC is enabled is > a problem for many users with their new signing algorithm in use that seemed to > be triggered late this week. > > Even Fedora, running 9.5.1-2.p2 requires dnssec-validate no to resolve .gov > domains and trying to import the public key for .gov yields an invalid > algorithm message. named fails to handle "gov." domain only when you use DLV. If you try import key with unknown algorithm it fails during startup (it is expected behavior). 9.5.1-2.P2 in Fedora should work fine. If it hits unknown algorithm during DLV process it falls back to non-secure DNS as expected. If it doesn't work in your case open a bug report against Fedora and attach your log, please. An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2009-1420.html |