From 784dca6da17f0ffde56c5c49feb8eac4e680f075 Mon Sep 17 00:00:00 2001 From: bert hubert Date: Fri, 1 Jul 2016 11:50:04 +0200 Subject: [PATCH] some TLDs have only 1 NSEC3 record --- pdns/validate.cc | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pdns/validate.cc b/pdns/validate.cc index 6918f5f06a..ee326b321a 100644 --- a/pdns/validate.cc +++ b/pdns/validate.cc @@ -401,10 +401,13 @@ vState getKeysFor(DNSRecordOracle& dro, const DNSName& zone, keyset_t &keyset) auto nsec3 = std::dynamic_pointer_cast(r); string h = hashQNameWithSalt(nsec3->d_salt, nsec3->d_iterations, qname); + // cerr<<"Salt length: "<d_salt.length()<<", iterations: "<d_iterations<<", hashed: "<d_nexthash) || - (nsec3->d_nexthash > h && beginHash > nsec3->d_nexthash)) { //wrap + (nsec3->d_nexthash > h && beginHash > nsec3->d_nexthash) || //wrap + beginHash == nsec3->d_nexthash) // "we have only 1 NSEC3 record, LOL!" + { LOG("Denies existence of DS!"<