chiark / gitweb /
resolved: don't attempt to send queries for DNSSEC RR types to servers not supporting...
authorLennart Poettering <lennart@poettering.net>
Fri, 8 Jan 2016 16:10:49 +0000 (17:10 +0100)
committerSven Eden <yamakuzure@gmx.net>
Wed, 17 May 2017 13:22:15 +0000 (15:22 +0200)
commit0800dbe33c6e875b9c11a9baa7c296ecd8640415
tree953a35f662f024048697242ab2d918ba1b95dfa9
parentd0774825d606da65eef44ebdd3d8753907951896
resolved: don't attempt to send queries for DNSSEC RR types to servers not supporting them

If we already degraded the feature level below DO don't bother with sending requests for DS, DNSKEY, RRSIG, NSEC, NSEC3
or NSEC3PARAM RRs. After all, we cannot do DNSSEC validation then anyway, and we better not press a legacy server like
this with such modern concepts.

This also has the benefit that when we try to validate a response we received using DNSSEC, and we detect a limited
server support level while doing so, all further auxiliary DNSSEC queries will fail right-away.
src/libelogind/sd-bus/bus-common-errors.h