Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
On Fri, Mar 1, 2024 at 12:38 AM Matt Nordhoff wrote: > On Thu, Feb 29, 2024 at 9:40 PM Ondřej Surý wrote: > > Hey, > > > > BIND 9 supports a fixed rrset ordering (that is keeping the order of the > > RRSets from the zone file). It has to be configured > > at the compile time, it takes more

Re: fixed rrset ordering - is this still a thing?

2024-02-29 Thread Matt Nordhoff via bind-users
On Thu, Feb 29, 2024 at 9:40 PM Ondřej Surý wrote: > Hey, > > BIND 9 supports a fixed rrset ordering (that is keeping the order of the > RRSets from the zone file). It has to be configured > at the compile time, it takes more memory (to record that order) and it's a > #ifdef all over the

KeyTrap fix breaks resolving semi-bogus paste.debian.net/snow-crash.org

2024-02-14 Thread Matt Nordhoff via bind-users
Hello, I'm not sure if this is a bug or a feature, but the recent CVE fixes prevent resolving paste.debian.net with DNSSEC validation on. It is a CNAME: $ dig +short paste.debian.net apu.snow-crash.org. p.snow-crash.org. 148.251.236.38 debian.net is fine, but snow-crash.org is misconfigured: