Open RoyArends opened 6 years ago
Users of your software that enable DNSSEC will not be able to validate DNS after October the 11th 2018.
Your repository contains a dnssec_test.py file without the new DNSSEC trust-anchors:
resolver.add_ta(". IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5")
It should also include:
resolver.add_ta(". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D")
More information can be found at: https://www.icann.org/resources/pages/ksk-rollover
Please don’t hesitate to get in touch.
Warmly,
Roy Arends ICANN
I originally planned to create some upstream patches for dns over tls, but never finished them. It was not intended to be used by end-users. I will archive this repository to make this more clear.
Users of your software that enable DNSSEC will not be able to validate DNS after October the 11th 2018.
Your repository contains a dnssec_test.py file without the new DNSSEC trust-anchors:
resolver.add_ta(". IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5")
It should also include:
resolver.add_ta(". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D")
More information can be found at: https://www.icann.org/resources/pages/ksk-rollover
Please don’t hesitate to get in touch.
Warmly,
Roy Arends ICANN