Mats Dufberg
Mats Dufberg
F2F: Remove the wish list.
Wait for solution.
I think the simplest solution is to put a [dnsdist] in front of [rbldnsd]. [dnsdist]: https://dnsdist.org/ [rbldnsd]: https://github.com/spamhaus/rbldnsd/blob/master/README
> You mean a [dnsdist](https://dnsdist.org/)? Yes, of course. I mixed things up when editing. I have corrected above. Thank you, @bortzmeyer!
``` $ zonemaster-cli atiger.se --show-testcase --level error --test dnssec --raw 9.34 ERROR DNSSEC09 DS09_NO_MATCHING_DNSKEY keytag=53612; ns_ip_list=185.42.137.98;194.58.192.46;194.58.198.32;2a01:3f0:400::32;2a01:3f1:3032::53;2a01:3f1:46::53 9.36 CRITICAL UNSPECIFIED MODULE_ERROR module=DNSSEC; msg=Key list is empty at /usr/local/share/perl/5.26.1/Zonemaster/Engine/Test/DNSSEC.pm line 2627. ```...
The message "DS09_NO_MATCHING_DNSKEY" is outputted on ERROR level from [DNSSEC09]. There is, however, no support in [RFC 4035#section-2.2] that it is an error to have RRSIG records that have no...
Update Basic02 with explicit message tags.
Will be resolved by #1085.
Transferred the issue from Zonemaster-Engine since this a question on the specification, not the implementation.
> Perhaps it should also warn if all name servers are in a single IPv4 /24 or IPv6 /48. Thank you for your proposal. We will look into it. Maybe...