+17 September 2010: Wouter
+ - DLV has downgrade protection again, because the RFC says so.
+
16 September 2010: Wouter
- Algorithm rollover operational reality intrudes, for trust-anchor,
5011-store, and DLV-anchor if one key matches it's good enough.
vq->state = VAL_VALIDATE_STATE;
return;
}
- /* protect DS against downgrade, but DLV does not(for key scrapers) */
- downprot = (ntohs(vq->ds_rrset->rk.type) == LDNS_RR_TYPE_DS);
+ downprot = 1;
vq->key_entry = val_verify_new_DNSKEYs(qstate->region, qstate->env,
ve, dnskey, vq->ds_rrset, downprot, &reason);