mirror of
https://github.com/pi-hole/dnsmasq.git
synced 2025-12-19 18:28:25 +00:00
Log BOGUS validation result when upstream sends SERVFAIL.
This commit is contained in:
@@ -1127,6 +1127,9 @@ int dnssec_validate_reply(time_t now, struct dns_header *header, size_t plen, ch
|
||||
int type1, class1, rdlen1, type2, class2, rdlen2;
|
||||
int i, j, rc, have_nsec, have_nsec_equal, cname_count = 5;
|
||||
|
||||
if (RCODE(header) == SERVFAIL)
|
||||
return STAT_BOGUS;
|
||||
|
||||
if ((RCODE(header) != NXDOMAIN && RCODE(header) != NOERROR) || ntohs(header->qdcount) != 1)
|
||||
return STAT_INSECURE;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user