dnssec: special SOA and DNSKEY handling only in zone APEX
Prior to this change, non-apex DNSKEYs were not signed and invalid NSEC records were generated for these nodes.
Showing
- src/knot/dnssec/zone-sign.c 10 additions, 9 deletionssrc/knot/dnssec/zone-sign.c
- src/knot/zone/node.c 23 additions, 0 deletionssrc/knot/zone/node.c
- src/knot/zone/node.h 10 additions, 4 deletionssrc/knot/zone/node.h
- src/knot/zone/zone-contents.c 5 additions, 0 deletionssrc/knot/zone/zone-contents.c
Loading
Please register or sign in to comment