dnssec: avoid checking existing correct RRSIGs twice
...once in remove_expired_rrsigs(), once in add_missing_rrsigs() this is important because unlike RSASHA, with ECDSA is checking signature far slower than creating one little side effect: signatures of DNSKEY record by ZSK are always removed
Showing
- src/knot/dnssec/zone-sign.c 43 additions, 100 deletionssrc/knot/dnssec/zone-sign.c
- tests-extra/tests/dnssec/no_resign/data/example.zone 0 additions, 1 deletiontests-extra/tests/dnssec/no_resign/data/example.zone
- tests-extra/tests/dnssec/no_resign/data/keys/lock.mdb 0 additions, 0 deletionstests-extra/tests/dnssec/no_resign/data/keys/lock.mdb
- tests-extra/tools/zone_generate.py 1 addition, 1 deletiontests-extra/tools/zone_generate.py
Loading
Please register or sign in to comment