From: Peter van Dijk Date: Mon, 11 Jan 2016 16:51:08 +0000 (+0100) Subject: Mark dnssec-failed.org as bogus X-Git-Tag: dnsdist-1.0.0-alpha2~90^2~2 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=79a7d667b4fb7384b837c9475b36399514dcbeac;p=thirdparty%2Fpdns.git Mark dnssec-failed.org as bogus Do not throw away bogus result from getKeysFor --- diff --git a/pdns/validate-recursor.cc b/pdns/validate-recursor.cc index 232549af25..4b951d97e2 100644 --- a/pdns/validate-recursor.cc +++ b/pdns/validate-recursor.cc @@ -38,19 +38,20 @@ vState validateRecords(const vector& recs) SRRecordOracle sro; + vState state; if(numsigs) { for(const auto& csp : cspmap) { for(const auto& sig : csp.second.signatures) { - getKeysFor(sro, sig->d_signer, keys); // XXX check validity here - // cerr<<"! state = "<d_signer, keys); // XXX check validity here + // cerr<<"! state = "<d_name, keys); // um WHAT DOES THIS MEAN - try first qname?? + state = getKeysFor(sro, recs.begin()->d_name, keys); // um WHAT DOES THIS MEAN - try first qname?? // cerr<<"! state = "<