From c65b77c87fbb411cfcbd770ac4a46b7a6560aaf9 Mon Sep 17 00:00:00 2001 From: Kevin Darbyshire-Bryant Date: Sat, 11 May 2019 17:05:23 +0000 Subject: [PATCH] dnssec: add hostname info to insecure DS warning Make the existing "insecure DS received" warning more informative by reporting the domain name reporting the issue. This may help identify a problem with a specific domain or server configuration. Signed-off-by: Kevin Darbyshire-Bryant --- src/dnssec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/dnssec.c b/src/dnssec.c index 6824e0a..53420e4 100644 --- a/src/dnssec.c +++ b/src/dnssec.c @@ -899,7 +899,7 @@ int dnssec_validate_ds(time_t now, struct dns_header *header, size_t plen, char if (rc == STAT_INSECURE) { - my_syslog(LOG_WARNING, _("Insecure DS reply received, do upstream DNS servers support DNSSEC?")); + my_syslog(LOG_WARNING, _("Insecure DS reply received for %s, check domain configuration and upstream DNS server DNSSEC support"), name); rc = STAT_BOGUS; }