Hi, I’ve noticed that the 1.1.1.1/help was not working when running through dnsmasq.
It appears there’s a bug in the logic when a CNAME is returned from an unsigned zone. I think there’s another bug in there in general that it returns BOGUS when a zone is SECURE also? Anyway, please see my attached patch which remedies my problem and I believe implements DNSSEC as it was intended. Thanks, Chris.
dnssec.patch
Description: Binary data
_______________________________________________ Dnsmasq-discuss mailing list Dnsmasq-discuss@lists.thekelleys.org.uk https://lists.thekelleys.org.uk/cgi-bin/mailman/listinfo/dnsmasq-discuss