Simon Kelley
|
83349b8aa4
|
Further tidying of AD and DO bit handling.
|
2014-02-10 21:02:01 +00:00 |
|
Simon Kelley
|
7fa836e105
|
Handle validation when more one key is needed.
|
2014-02-10 20:11:24 +00:00 |
|
Simon Kelley
|
e243c072b5
|
AD bit in queries handled as RFC6840 p5.7
|
2014-02-06 18:14:09 +00:00 |
|
Simon Kelley
|
610e782a29
|
Fix stack-smashing crash in DNSSEC. Thanks to Henk Jan Agteresch.
|
2014-02-06 14:45:17 +00:00 |
|
Simon Kelley
|
81a883fda3
|
Format tweak.
|
2014-02-03 21:17:04 +00:00 |
|
Simon Kelley
|
8d718cbb3e
|
Nasty cache failure and memory leak with DNSSEC.
|
2014-02-03 16:27:37 +00:00 |
|
Simon Kelley
|
97bc798b05
|
Init ->dependent field in frec allocation.
|
2014-01-31 10:19:52 +00:00 |
|
Simon Kelley
|
6938f3476e
|
Don't mark answers as DNSEC validated if DNS-doctored.
|
2014-01-26 22:47:39 +00:00 |
|
Simon Kelley
|
7d23a66ff0
|
Remove --dnssec-permissive, pointless if we don't set CD upstream.
|
2014-01-26 09:33:21 +00:00 |
|
Simon Kelley
|
703c7ff429
|
Fix to last commit.
|
2014-01-25 23:46:23 +00:00 |
|
Simon Kelley
|
8a9be9e493
|
Replace CRC32 with SHA1 for spoof detection in DNSSEC builds.
|
2014-01-25 23:17:21 +00:00 |
|
Simon Kelley
|
5b3bf92101
|
--dnssec-debug
|
2014-01-25 17:03:07 +00:00 |
|
Simon Kelley
|
0744ca66ad
|
More DNSSEC caching logic, and avoid repeated validation of DS/DNSKEY
|
2014-01-25 16:40:15 +00:00 |
|
Simon Kelley
|
39048ad10b
|
bug fix, avoids infinite loop in forwarding code.
|
2014-01-21 17:33:58 +00:00 |
|
Simon Kelley
|
5d3b87a484
|
Better handling of truncated DNSSEC replies.
|
2014-01-20 11:57:23 +00:00 |
|
Simon Kelley
|
6c0cb858c1
|
Trivial format fix
|
2014-01-17 14:40:46 +00:00 |
|
Simon Kelley
|
e0c0ad3b5e
|
UDP retries for DNSSEC
|
2014-01-16 22:42:07 +00:00 |
|
Simon Kelley
|
4619d94622
|
Fix SEGV and failure to validate on x86_64.
|
2014-01-16 19:53:06 +00:00 |
|
Simon Kelley
|
a25720a34a
|
protocol handling for DNSSEC
|
2014-01-14 23:13:55 +00:00 |
|
Simon Kelley
|
795501bc86
|
AD bit handling when doing validation.
|
2014-01-08 18:11:55 +00:00 |
|
Simon Kelley
|
c47e3ba446
|
Update copyright for 2014.
|
2014-01-08 17:07:54 +00:00 |
|
Simon Kelley
|
f1668d2786
|
New source port for DNSSEC-originated queries.
|
2014-01-08 16:53:27 +00:00 |
|
Simon Kelley
|
7d7b7b31e5
|
DNSSEC for TCP queries.
|
2014-01-08 15:57:36 +00:00 |
|
Simon Kelley
|
60b68069cf
|
Rationalise DNS packet-buffer size calculations.
|
2014-01-08 12:10:28 +00:00 |
|
Simon Kelley
|
871417d45d
|
Handle truncated replies in DNSSEC validation.
|
2014-01-08 11:22:32 +00:00 |
|
Simon Kelley
|
0fc2f31368
|
First functional DNSSEC - highly alpha.
|
2014-01-08 10:26:58 +00:00 |
|
Simon Kelley
|
c3e0b9b6e7
|
backup
|
2013-12-31 13:50:39 +00:00 |
|
Simon Kelley
|
9d633048fe
|
Saving progress
|
2013-12-13 15:36:55 +00:00 |
|
Simon Kelley
|
c352dd8f1a
|
Merge branch 'master' into dnssec
|
2013-12-12 12:16:17 +00:00 |
|
Simon Kelley
|
3a2371527f
|
Commit to allow master merge.
|
2013-12-12 12:15:50 +00:00 |
|
Simon Kelley
|
2329bef5ba
|
Check arrival interface of IPv6 requests, even in --bind-interfaces.
|
2013-12-03 13:41:16 +00:00 |
|
Vladislav Grishenko
|
3b19596122
|
Fix compiler warnings.
|
2013-11-26 11:08:21 +00:00 |
|
Simon Kelley
|
5a4120dbfb
|
Merge branch 'master' into dnssec
Conflicts:
src/dnsmasq.h
src/forward.c
src/option.c
|
2013-10-25 13:16:27 +01:00 |
|
Simon Kelley
|
6008bdbbc1
|
Fix botch in determining if auth query is local.
|
2013-10-21 21:47:03 +01:00 |
|
Simon Kelley
|
19b1689161
|
Don't filter by subnet when handling local queries for auth-zones.
|
2013-10-20 10:19:39 +01:00 |
|
Simon Kelley
|
b485ed97aa
|
Always answer queries for authoritative zones locally, never forward.
|
2013-10-18 22:00:39 +01:00 |
|
Simon Kelley
|
ed4c0767b1
|
--add-subnet option.
|
2013-10-08 20:46:34 +01:00 |
|
Giovanni Bajo
|
e292e93d35
|
Initial dnssec structure.
|
2013-08-20 15:41:18 +01:00 |
|
Giovanni Bajo
|
237724c0c7
|
Rename existing DNSSEC macros into DNSSEC_PROXY.
|
2013-08-20 15:39:44 +01:00 |
|
Marcelo Salhab Brogliato
|
0da5e8979b
|
Log forwarding table overflows.
|
2013-05-31 11:49:06 +01:00 |
|
Simon Kelley
|
115ac3e4d7
|
Generalise --interface-name to cope with IPv6 addresses.
|
2013-05-20 11:28:32 +01:00 |
|
Simon Kelley
|
3f2873d42c
|
Handle IPv4 interface-address labels in Linux.
|
2013-05-14 11:28:47 +01:00 |
|
Giacomo Tazzari
|
797a7afba4
|
Fix crash on SERVFAIL when --conntrack in use.
|
2013-04-22 13:16:37 +01:00 |
|
Simon Kelley
|
4b5ea12e90
|
Send TCP DNS messages in one write() call. Stops TCP stream fragmenting.
This is an optimisation, not a bugfix. Thanks to Jim Bos for spotting it.
|
2013-04-22 10:22:55 +01:00 |
|
Simon Kelley
|
7e5664bdbc
|
Fix trivial access of un-initialised memory.
Thanks to sven falpin for finding this.
|
2013-04-09 22:28:04 +01:00 |
|
Jason A. Donenfeld
|
13d86c7372
|
Add --ipset option.
|
2013-02-22 21:44:08 +00:00 |
|
Simon Kelley
|
61744359de
|
Change copyright messages to include 2013.
|
2013-01-31 14:34:40 +00:00 |
|
Simon Kelley
|
e25db1f273
|
Handle wrong interface for locally-routed packets.
|
2013-01-29 22:10:26 +00:00 |
|
Simon Kelley
|
4820dce97a
|
Make authoritative stuff a compile-time option.
|
2012-12-18 18:30:30 +00:00 |
|
Simon Kelley
|
496787677e
|
Zone-transfer peer restriction option.
|
2012-12-09 18:31:10 +00:00 |
|