    • Petr Špaček's avatar
      Merge branch 'ta_sentinel-update' into 'master' · 314baab2
      Petr Špaček authored
      val_ta_sentinel* tests: update to RFC draft -14
      See merge request !117
    • Petr Špaček's avatar
      unbound: disable local-zone test. · 880302df
      Petr Špaček authored
      test. TLD is used by many tests so we need to explicitly disable the
      built-in local-zone.
    • Petr Špaček's avatar
      val_ta_sentinel* tests: extend tests to cover !AD and +CD · d4ffae30
      Petr Špaček authored
      Sentinel must not require AD/DO bits set in the queries otherwise it
      will not work with stubs and web browsers deployed in 2018.
      Tests were extended with +CD cases to make sure forwarding
      configurations behave as specified by the draft -14.
    • Vladimír Čunát's avatar
      val_ta_sentinel_insecure: fix problem with NTA · 31445c99
      Vladimír Čunát authored
      It didn't work properly due to negative trust anchor being outside a
      zone cut, so I move the tested names to an unsigned zone.
      root.db: the only real change was addition of "unsigned." delegation,
      causing root-key-sentinel-not-ta-48409.test. NSEC to get modified.
      The other changes are just reordering and drops of "resign=" lines;
      I'm not sure why dnssec-signzone decided to do such changes.
      (I didn't put the unsigned. zone into any zone file.)