Bug#1092914: knot: Fails to serve dnssec'd zone with a DNAME at the toplevel

2025-01-13 Thread Daniel Salzman
Hi, Thanks for the bug report. Please note that using NSEC3 for your trivial zone doesn't make sense. So it's not a workaround :-) Daniel Knot DNS OpenPGP_0x10BB7AF6FEBBD6AB.asc Description: OpenPGP public key OpenPGP_signature.asc Description: OpenPGP digital signature

Bug#1092914: knot: Fails to serve dnssec'd zone with a DNAME at the toplevel

2025-01-13 Thread Uwe Kleine-König
Package: knot Version: 3.2.6-1 Severity: normal Hello, knot fails to load a dnssec'd zone from my primary that has a DNAME RR for @ and is using NSEC3. The complete zone looks as follows (AXFR from the primary running powerdns): $ dig xn--kleine-knig-yfb.de AXFR ; <<>> DiG 9.18