[Pdns-users] First use of the PowerDNS 'upgrade now' system today

2015-04-24 Thread bert hubert
Hi everybody, In response to the security releases we did yesterday, we've activated the built-in PowerDNS 'upgrade now' system for the first time, and we have a question for you. This system is described in http://blog.powerdns.com/2014/10/22/powerdns-security-status-polling/ and documented on

[Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread Michael Ströder
HI! We're currently testing DNSSEC validation with libunbound 1.5.3 with all the RRs retrieved through a pdns-recursor (also tested 3.7.2). It seems that 1. libunbound does not explicitly retrieve the RRSIG RRs and 2. pdns-recursor does not return them when not explicitly request (qtype

Re: [Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread leen
On 2015-04-24 21:35, Michael Ströder wrote: Michael Ströder wrote: We're currently testing DNSSEC validation with libunbound 1.5.3 with all the RRs retrieved through a pdns-recursor (also tested 3.7.2). It seems that 1. libunbound does not explicitly retrieve the RRSIG RRs and 2.

Re: [Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread Michael Ströder
Michael Ströder wrote: We're currently testing DNSSEC validation with libunbound 1.5.3 with all the RRs retrieved through a pdns-recursor (also tested 3.7.2). It seems that 1. libunbound does not explicitly retrieve the RRSIG RRs and 2. pdns-recursor does not return them when not explicitly

Re: [Pdns-users] DNSSEC, pdns-recursor and libunbound

2015-04-24 Thread bert hubert
On Fri, Apr 24, 2015 at 11:07:46PM +0200, l...@consolejunkie.net wrote: The answer I got was: The validation is in comparison the easy part, changing the recursor to return the DNSSEC-information is more work. We're on it people!