Hi all,

we'd like to inform you about recently found bug in Knot DNS 2.9.x.

The bug affects automatic key roll-overs when automatic key management is configured https://www.knot-dns.cz/docs/2.9/singlehtml/index.html#automatic-dnssec-signing

The ZSK, CSK or algorithm roll-over might be finished too early, so that DNSKEY and RRSIG records in resolvers' caches get out of sync, leading to temporary DNSSEC validation failure.

Affected versions are Knot DNS 2.9.0 -- 2.9.4.

We will release fixing version 2.9.5 soon.

In the meantime, we recommend to apply the workaround: set the configuration option zone-max-ttl https://www.knot-dns.cz/docs/2.9/singlehtml/index.html#zone-max-ttl explicitly to a value greater or equal to maximal TTL among all records in the zone. (Remove the workaround once upgraded to fixed version.)

Many thanks to Anand Buddhdev from RIPE NCC for finding this bug.

Caring regards,

Libor Peltan
CZ.NIC

--
https://lists.nic.cz/mailman/listinfo/knot-dns-users

Reply via email to