]> git.ipfire.org Git - thirdparty/systemd.git/commit - src/resolve/resolved-dns-dnssec.c
resolved: introduce a dnssec_mode setting per scope
authorLennart Poettering <lennart@poettering.net>
Thu, 3 Dec 2015 18:51:04 +0000 (19:51 +0100)
committerLennart Poettering <lennart@poettering.net>
Thu, 3 Dec 2015 20:17:49 +0000 (21:17 +0100)
commit24710c48ed16be5fa461fbb303a744a907541daf
tree3331d39fd5762c7d5fe9babf50dd463a0151b011
parent896c567247371cc14e49774c3b844a7038c37a60
resolved: introduce a dnssec_mode setting per scope

The setting controls which kind of DNSSEC validation is done: none at
all, trusting the AD bit, or client-side validation.

For now, no validation is implemented, hence the setting doesn't do much
yet, except of toggling the CD bit in the generated messages if full
client-side validation is requested.
src/resolve/resolved-conf.c
src/resolve/resolved-conf.h
src/resolve/resolved-dns-dnssec.c
src/resolve/resolved-dns-dnssec.h
src/resolve/resolved-dns-packet.c
src/resolve/resolved-dns-packet.h
src/resolve/resolved-dns-scope.h
src/resolve/resolved-dns-server.h
src/resolve/resolved-dns-transaction.c
src/resolve/resolved-gperf.gperf
src/resolve/resolved.conf.in