[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2021-06-16 Thread Christian Ehrhardt 
** Tags removed: server-next -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled without support for EdDSA DNSSEC keys To manage notifications about this bug go to:

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-09-03 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~sergiodj/ubuntu/+source/bind9/+git/bind9/+merge/390274 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-09-03 Thread Simon Déziel
For what it's worth, Bionic's bind9 version should support EdDSA according to https://bind.isc.org/doc/arm/9.11/man.dnssec-keygen.html I dunno how well it would work on 9.11.3 though. It would be nice to have EdDSA support enabled in Bionic if that can work reliably. It would help with the

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-03-04 Thread Andreas Hasenack
It's a valid request, I'm just not sure if the version of bind in bionic is good enough for this support. I vaguely remember reading somewhere that certain encryption types were not working well in certain versions of bind9 (sorry, very vague, I know). Because of that I'm confirming the bug, but

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-03-04 Thread Andreas Hasenack
It's a valid request, I'm just not sure if the version of bind in bionic is good enough for this support. I vaguely remember reading somewhere that certain encryption types were not working well in certain versions of bind9 (sorry, very vague, I know). Because of that I'm confirming the bug, but

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-02-27 Thread Christian Ehrhardt 
** Tags added: server-next -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled without support for EdDSA DNSSEC keys To manage notifications about this bug go to:

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-02-27 Thread Christian Ehrhardt 
It was never in Bionic and only added as a feature later. $ git show pkg/ubuntu/bionic-devel:debian/rules | grep eddsa --with-eddsa=no \ --with-eddsa=no \ I think that would break the SRU rules, but I'll add a bionic task and assign ahasenack to finally decide on

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2020-02-19 Thread Michael Glanznig
This is also a problem in bionic. At least with bind9utils. On the system I tested I don't have bind9 available. I wanted to create a Ed25519 ZSK. Could this be backported? I wanted to add an Affects Link, but got an error instead. -- You received this bug notification because you are a member

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-16 Thread Launchpad Bug Tracker
This bug was fixed in the package bind9 - 1:9.11.5.P1+dfsg-1ubuntu2.4 --- bind9 (1:9.11.5.P1+dfsg-1ubuntu2.4) disco; urgency=medium * d/rules: add back EdDSA support (LP: #1825712) -- Andreas Hasenack Fri, 26 Apr 2019 14:20:00 + ** Changed in: bind9 (Ubuntu Disco)

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-09 Thread Andreas Hasenack
Disco verification: First, reproducing the bug: ubuntu@disco-bind-1825712:~$ apt-cache policy bind9 bind9: Installed: 1:9.11.5.P1+dfsg-1ubuntu2.3 Candidate: 1:9.11.5.P1+dfsg-1ubuntu2.3 Version table: *** 1:9.11.5.P1+dfsg-1ubuntu2.3 500 500 http://br.archive.ubuntu.com/ubuntu

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-09 Thread Andreas Hasenack
Disco verification: First, reproducing the bug: ubuntu@disco-bind-1825712:~$ apt-cache policy bind9 bind9: Installed: 1:9.11.5.P1+dfsg-1ubuntu2.3 Candidate: 1:9.11.5.P1+dfsg-1ubuntu2.3 Version table: *** 1:9.11.5.P1+dfsg-1ubuntu2.3 500 500 http://br.archive.ubuntu.com/ubuntu

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-09 Thread Teemu Torma
This fixes the ed25519 zone signing for me. bind9 (1:9.11.5.P1+dfsg-1ubuntu2.4) disco; urgency=medium * d/rules: add back EdDSA support (LP: #1825712) -- Andreas Hasenack Fri, 26 Apr 2019 14:20:00 + ** Tags removed: verification-needed-disco **

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-08 Thread Brian Murray
Hello Teemu, or anyone else affected, Accepted bind9 into disco-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1 +dfsg-1ubuntu2.4 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-03 Thread Andreas Hasenack
** Merge proposal unlinked: https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871 -- You received this bug notification because you are a member of Ubuntu Server, which is subscribed to bind9 in Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-03 Thread Andreas Hasenack
** Merge proposal unlinked: https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-05-02 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366871 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-29 Thread Launchpad Bug Tracker
This bug was fixed in the package bind9 - 1:9.11.5.P1+dfsg-1ubuntu4 --- bind9 (1:9.11.5.P1+dfsg-1ubuntu4) eoan; urgency=medium * d/rules: add back EdDSA support (LP: #1825712) -- Andreas Hasenack Fri, 26 Apr 2019 14:04:37 + ** Changed in: bind9 (Ubuntu) Status: In

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366414 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
** Description changed: - In Ubuntu Disco Dingo, bind9_9.11.5.P1+dfsg-1ubuntu2 is built --with- - eddsa=no, thus breaking DNSSEC zones using Ed25519 keys. This used to - work fine in Cosmic Cattlefish. + [Impact] + Bind9, either when acting as a resolver, or a master for a zone, does not have

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
** Description changed: - In Ubuntu Disco Dingo, bind9_9.11.5.P1+dfsg-1ubuntu2 is built --with- - eddsa=no, thus breaking DNSSEC zones using Ed25519 keys. This used to - work fine in Cosmic Cattlefish. + [Impact] + Bind9, either when acting as a resolver, or a master for a zone, does not have

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
** Changed in: bind9 (Ubuntu) Status: Triaged => In Progress ** Changed in: bind9 (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: bind9 (Ubuntu Disco) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: bind9 (Ubuntu Disco)

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
** Changed in: bind9 (Ubuntu) Status: Triaged => In Progress ** Changed in: bind9 (Ubuntu) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: bind9 (Ubuntu Disco) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: bind9 (Ubuntu Disco)

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Launchpad Bug Tracker
** Merge proposal linked: https://code.launchpad.net/~ahasenack/ubuntu/+source/bind9/+git/bind9/+merge/366410 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
This is also a good test, and doesn't require networking: dnssec-keygen -a ED25519 example.com -- You received this bug notification because you are a member of Ubuntu Server, which is subscribed to bind9 in Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled without

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-23 Thread Andreas Hasenack
This is also a good test, and doesn't require networking: dnssec-keygen -a ED25519 example.com -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1825712 Title: bind9 is compiled without support for

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Teemu Torma
I don't have simple test case, I use unbound as resolver. I noticed the problem with my authoritative bind9 server failing to sign zones using Ed25519 keys with "unsupported algorithm" or similar error. I just had to rebuild bind9 with eddsa support (and add the symbol) to keep on going. But I

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Maybe this test is good. With current disco packages: $ delv +dnssec +multiline @127.0.0.1 ed25519.nl ;; validating ed25519.nl/A: no valid signature found ; unsigned answer ed25519.nl. 3591 IN A 77.72.150.82 ed25519.nl. 3200171710 IN RRSIG A 15 2 3600 (

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Maybe this test is good. With current disco packages: $ delv +dnssec +multiline @127.0.0.1 ed25519.nl ;; validating ed25519.nl/A: no valid signature found ; unsigned answer ed25519.nl. 3591 IN A 77.72.150.82 ed25519.nl. 3200171710 IN RRSIG A 15 2 3600 (

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Do you have an example at hand of such a breakage? It will make the testing and SRU easier. Something like using dig with @localhost and asking for info for such a public zone. -- You received this bug notification because you are a member of Ubuntu Server, which is subscribed to bind9 in

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Do you have an example at hand of such a breakage? It will make the testing and SRU easier. Something like using dig with @localhost and asking for info for such a public zone. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Thanks for filing this bug in Ubuntu. You are right, this should have been enabled back. ** Changed in: bind9 (Ubuntu) Status: New => Triaged ** Changed in: bind9 (Ubuntu) Importance: Undecided => Medium ** Also affects: bind9 (Ubuntu Disco) Importance: Undecided Status:

[Bug 1825712] Re: bind9 is compiled without support for EdDSA DNSSEC keys

2019-04-22 Thread Andreas Hasenack
Thanks for filing this bug in Ubuntu. You are right, this should have been enabled back. ** Changed in: bind9 (Ubuntu) Status: New => Triaged ** Changed in: bind9 (Ubuntu) Importance: Undecided => Medium ** Also affects: bind9 (Ubuntu Disco) Importance: Undecided Status: