Simon Kelley fe3992f9fa Return INSECURE, rather than BOGUS when DS proved not to exist.
Return INSECURE when validating DNS replies which have RRSIGs, but
when a needed DS record in the trust chain is proved not to exist.
It's allowed for a zone to set up DNSKEY and RRSIG records first, then
add a DS later, completing the chain of trust.

Also, since we don't have the infrastructure to track that these
non-validated replies have RRSIGS, don't cache them, so we don't
provide answers with missing RRSIGS from the cache.
2015-04-03 21:25:05 +01:00
2014-08-12 18:30:44 +01:00
2015-02-12 18:30:32 +00:00
2012-04-02 20:40:34 +01:00
2015-03-30 07:52:21 +01:00
2012-01-05 17:31:15 +00:00
2012-01-05 17:31:10 +00:00
2012-01-05 17:31:13 +00:00
2013-04-15 14:31:52 +01:00
2015-02-01 00:15:16 +00:00
2012-01-05 17:31:15 +00:00
2012-01-05 22:00:08 +00:00
Description
No description provided
17 MiB
Languages
C 94.2%
Perl 2.3%
HTML 1.2%
Shell 1.1%
Makefile 0.6%
Other 0.6%