+Knot Resolver 5.x.y (2021-0m-dd)
+================================
+
+Bugfixes
+--------
+- trust_anchors.set_insecure: improve precision (#673, !1177)
+
+
Knot Resolver 5.3.2 (2021-05-05)
================================
#include "lib/dnssec/nsec.h"
#include "lib/dnssec/nsec3.h"
+#include "lib/dnssec/ta.h"
#include "lib/dnssec.h"
#include "lib/layer.h"
#include "lib/resolve.h"
continue; /* these are already OK */
}
+ if (!knot_dname_is_equal(qry->zone_cut.name, rr->owner)/*optim.*/
+ && !kr_ta_covers_qry(qry->request->ctx, rr->owner, rr->type)) {
+ /* We have NTA "between" our (perceived) zone cut and the RR. */
+ kr_rank_set(&entry->rank, KR_RANK_INSECURE);
+ continue;
+ }
+
if (rr->type == KNOT_RRTYPE_RRSIG) {
const knot_dname_t *signer_name = knot_rrsig_signer_name(rr->rrs.rdata);
if (!knot_dname_is_equal(vctx->zone_name, signer_name)) {