** Tags removed: server-next
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled without support for EdDSA DNSSEC keys
To manage notifications about this bug go to:
** Merge proposal linked:
https://code.launchpad.net/~sergiodj/ubuntu/+source/bind9/+git/bind9/+merge/390274
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled
For what it's worth, Bionic's bind9 version should support EdDSA according to
https://bind.isc.org/doc/arm/9.11/man.dnssec-keygen.html
I dunno how well it would work on 9.11.3 though.
It would be nice to have EdDSA support enabled in Bionic if that can
work reliably. It would help with the
It's a valid request, I'm just not sure if the version of bind in bionic
is good enough for this support. I vaguely remember reading somewhere
that certain encryption types were not working well in certain versions
of bind9 (sorry, very vague, I know). Because of that I'm confirming the
bug, but
It's a valid request, I'm just not sure if the version of bind in bionic
is good enough for this support. I vaguely remember reading somewhere
that certain encryption types were not working well in certain versions
of bind9 (sorry, very vague, I know). Because of that I'm confirming the
bug, but
** Tags added: server-next
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled without support for EdDSA DNSSEC keys
To manage notifications about this bug go to:
It was never in Bionic and only added as a feature later.
$ git show pkg/ubuntu/bionic-devel:debian/rules | grep eddsa
--with-eddsa=no \
--with-eddsa=no \
I think that would break the SRU rules, but I'll add a bionic task and
assign ahasenack to finally decide on
This is also a problem in bionic. At least with bind9utils. On the
system I tested I don't have bind9 available. I wanted to create a
Ed25519 ZSK. Could this be backported? I wanted to add an Affects Link,
but got an error instead.
--
You received this bug notification because you are a member
This bug was fixed in the package bind9 - 1:9.11.5.P1+dfsg-1ubuntu2.4
---
bind9 (1:9.11.5.P1+dfsg-1ubuntu2.4) disco; urgency=medium
* d/rules: add back EdDSA support (LP: #1825712)
-- Andreas Hasenack Fri, 26 Apr 2019 14:20:00
+
** Changed in: bind9 (Ubuntu Disco)
Disco verification:
First, reproducing the bug:
ubuntu@disco-bind-1825712:~$ apt-cache policy bind9
bind9:
Installed: 1:9.11.5.P1+dfsg-1ubuntu2.3
Candidate: 1:9.11.5.P1+dfsg-1ubuntu2.3
Version table:
*** 1:9.11.5.P1+dfsg-1ubuntu2.3 500
500 http://br.archive.ubuntu.com/ubuntu
Disco verification:
First, reproducing the bug:
ubuntu@disco-bind-1825712:~$ apt-cache policy bind9
bind9:
Installed: 1:9.11.5.P1+dfsg-1ubuntu2.3
Candidate: 1:9.11.5.P1+dfsg-1ubuntu2.3
Version table:
*** 1:9.11.5.P1+dfsg-1ubuntu2.3 500
500 http://br.archive.ubuntu.com/ubuntu
This fixes the ed25519 zone signing for me.
bind9 (1:9.11.5.P1+dfsg-1ubuntu2.4) disco; urgency=medium
* d/rules: add back EdDSA support (LP: #1825712)
-- Andreas Hasenack Fri, 26 Apr 2019 14:20:00
+
** Tags removed: verification-needed-disco
**
Hello Teemu, or anyone else affected,
Accepted bind9 into disco-proposed. The package will build now and be
available at https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1
+dfsg-1ubuntu2.4 in a few hours, and then in the -proposed repository.
Please help us by testing this new package. See
** Merge proposal unlinked:
https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871
--
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to bind9 in Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is
** Merge proposal unlinked:
https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled
** Merge proposal linked:
https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled
This bug was fixed in the package bind9 - 1:9.11.5.P1+dfsg-1ubuntu4
---
bind9 (1:9.11.5.P1+dfsg-1ubuntu4) eoan; urgency=medium
* d/rules: add back EdDSA support (LP: #1825712)
-- Andreas Hasenack Fri, 26 Apr 2019 14:04:37
+
** Changed in: bind9 (Ubuntu)
Status: In
** Merge proposal linked:
https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366414
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled
** Description changed:
- In Ubuntu Disco Dingo, bind9_9.11.5.P1+dfsg-1ubuntu2 is built --with-
- eddsa=no, thus breaking DNSSEC zones using Ed25519 keys. This used to
- work fine in Cosmic Cattlefish.
+ [Impact]
+ Bind9, either when acting as a resolver, or a master for a zone, does not
have
** Description changed:
- In Ubuntu Disco Dingo, bind9_9.11.5.P1+dfsg-1ubuntu2 is built --with-
- eddsa=no, thus breaking DNSSEC zones using Ed25519 keys. This used to
- work fine in Cosmic Cattlefish.
+ [Impact]
+ Bind9, either when acting as a resolver, or a master for a zone, does not
have
** Changed in: bind9 (Ubuntu)
Status: Triaged => In Progress
** Changed in: bind9 (Ubuntu)
Assignee: (unassigned) => Andreas Hasenack (ahasenack)
** Changed in: bind9 (Ubuntu Disco)
Assignee: (unassigned) => Andreas Hasenack (ahasenack)
** Changed in: bind9 (Ubuntu Disco)
** Changed in: bind9 (Ubuntu)
Status: Triaged => In Progress
** Changed in: bind9 (Ubuntu)
Assignee: (unassigned) => Andreas Hasenack (ahasenack)
** Changed in: bind9 (Ubuntu Disco)
Assignee: (unassigned) => Andreas Hasenack (ahasenack)
** Changed in: bind9 (Ubuntu Disco)
** Merge proposal linked:
https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366410
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled
This is also a good test, and doesn't require networking:
dnssec-keygen -a ED25519 example.com
--
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to bind9 in Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled without
This is also a good test, and doesn't require networking:
dnssec-keygen -a ED25519 example.com
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1825712
Title:
bind9 is compiled without support for
I don't have simple test case, I use unbound as resolver. I noticed the
problem with my authoritative bind9 server failing to sign zones using
Ed25519 keys with "unsupported algorithm" or similar error. I just had
to rebuild bind9 with eddsa support (and add the symbol) to keep on
going.
But I
Maybe this test is good.
With current disco packages:
$ delv +dnssec +multiline @127.0.0.1 ed25519.nl
;; validating ed25519.nl/A: no valid signature found
; unsigned answer
ed25519.nl. 3591 IN A 77.72.150.82
ed25519.nl. 3200171710 IN RRSIG A 15 2 3600 (
Maybe this test is good.
With current disco packages:
$ delv +dnssec +multiline @127.0.0.1 ed25519.nl
;; validating ed25519.nl/A: no valid signature found
; unsigned answer
ed25519.nl. 3591 IN A 77.72.150.82
ed25519.nl. 3200171710 IN RRSIG A 15 2 3600 (
Do you have an example at hand of such a breakage? It will make the
testing and SRU easier. Something like using dig with @localhost and
asking for info for such a public zone.
--
You received this bug notification because you are a member of Ubuntu
Server, which is subscribed to bind9 in
Do you have an example at hand of such a breakage? It will make the
testing and SRU easier. Something like using dig with @localhost and
asking for info for such a public zone.
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
Thanks for filing this bug in Ubuntu.
You are right, this should have been enabled back.
** Changed in: bind9 (Ubuntu)
Status: New => Triaged
** Changed in: bind9 (Ubuntu)
Importance: Undecided => Medium
** Also affects: bind9 (Ubuntu Disco)
Importance: Undecided
Status:
Thanks for filing this bug in Ubuntu.
You are right, this should have been enabled back.
** Changed in: bind9 (Ubuntu)
Status: New => Triaged
** Changed in: bind9 (Ubuntu)
Importance: Undecided => Medium
** Also affects: bind9 (Ubuntu Disco)
Importance: Undecided
Status:
32 matches
Mail list logo