-
Webmin Bind8 module does not recognize **rf** and **ri** tags in DMARC records (https://mxtoolbox.com/dmarc/details/dmarc-tags)
I propose the following patches:
``` diff
--- bind8-lib.pl-202201…
-
It would be a great add to have a look if the domain has TLSA record and if possible, even verify its validity
ada86 updated
6 months ago
-
Need to add some text requiring the chain lookup on SNI, if available.
-
1) Search for "is is" and "not not", a couple of typos.
2) For the section titled "Why use DANE for SMTP?", it seems to be backward. The section first notes the dangers, and it should perhaps instea…
-
-
One issue with allowing users to trust a validating resolver over a secure channel is that the secure connection itself relies on WebPKI which takes away the advantages provided by DANE.
Pinning is…
-
We had many problems with DNSSEC records not being updated automatically properly on many DNS changes, so they are probably related:
The general problem is that imho a DNSSEC-enabled zone should be…
-
@ookangzheng
1. Do you have TLSA records for your DNS endpoints?
2. You might want to look at The edns-tcp-keepalive EDNS0, as outlined by RFC [7828](https://tools.ietf.org/html/rfc7828), and its i…
obeho updated
3 years ago
-
Is Virtualmin really configuring Postfix so that it can fully enforce DANE and TLSA??
Reading the official Postfix README on the topic, it's very doubtful that Virtualmin really satisfies all the req…
-
Considering zone xxxx.com
Key count 2
Zone key in /var/lib/bind/Kxxxx.com.+005+29715.private
Age in days 7.24450231481481
Re-signing of xxxx.com failed : Re-signing failed : dnssec-signzon…