mirror of
https://github.com/isc-projects/bind9.git
synced 2026-02-25 02:42:33 -05:00
In some cases we want to keep expired signatures. For example, if the KSK is offline, we don't want to fall back to signing with the ZSK. We could remove the signatures, but in any case we end up with a broken zone. The change made for GL #763 prevented the behavior to sign the DNSKEY RRset with the ZSK if the KSK was offline (and signatures were expired). The change causes the definition of "having both keys": if one key is offline, we still consider having both keys, so we don't fallback signing with the ZSK if KSK is offline. That change also works the other way, if the ZSK is offline, we don't fallback signing with the KSK. This commit fixes that, so we only fallback signing zone RRsets with the KSK, not signing key RRsets with the ZSK. |
||
|---|---|---|
| .. | ||
| bind9 | ||
| dns | ||
| irs | ||
| isc | ||
| isccc | ||
| isccfg | ||
| ns | ||
| .gitignore | ||
| Makefile.am | ||
| unit-test-driver.sh.in | ||