Open RoyArends opened 6 years ago
Users of your software that enable DNSSEC will not be able to validate DNS after October the 11th 2018.
Your repository contains a dnssec_test.py file without the new DNSSEC trust-anchors:
resolver.add_ta(". IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5")
It should also include:
resolver.add_ta(". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D")
More information can be found at: https://www.icann.org/resources/pages/ksk-rollover
Please don’t hesitate to get in touch.
Warmly,
Roy Arends ICANN
I just noticed this. We'll get this once we update unbound from upstream, this file is unused here so no rush.
Users of your software that enable DNSSEC will not be able to validate DNS after October the 11th 2018.
Your repository contains a dnssec_test.py file without the new DNSSEC trust-anchors:
resolver.add_ta(". IN DS 19036 8 2 49AAC11D7B6F6446702E54A1607371607A1A41855200FD2CE1CDDE32F24E8FB5")
It should also include:
resolver.add_ta(". IN DS 20326 8 2 E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D")
More information can be found at: https://www.icann.org/resources/pages/ksk-rollover
Please don’t hesitate to get in touch.
Warmly,
Roy Arends ICANN