From ba558aefcc816bc16274b7a08f1d58cbb617c2a1 Mon Sep 17 00:00:00 2001 From: Tomas Krizek Date: Mon, 2 Nov 2020 11:17:59 +0100 Subject: [PATCH] distro/tests: update DNSSEC bogus test dnssec-failed.org domain uses RSA/SHA1 algorithm, which is considered insecure by Fedora 33+ policy. --- .../ansible-roles/knot_resolver/tasks/test_dnssec.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml b/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml index 990d4ca94..52bbbb2f8 100644 --- a/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml +++ b/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml @@ -1,15 +1,15 @@ --- # SPDX-License-Identifier: GPL-3.0-or-later -- name: dnssec_test dnssec-failed.org +cd returns NOERROR +- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. +cd returns NOERROR tags: - test - shell: kdig +cd @127.0.0.1 dnssec-failed.org + shell: kdig +cd @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl. register: res failed_when: '"status: NOERROR" not in res.stdout' -- name: dnssec_test dnssec-failed.org returns SERVFAIL +- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. returns SERVFAIL tags: - test - shell: kdig @127.0.0.1 dnssec-failed.org + shell: kdig @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl. register: res failed_when: '"status: SERVFAIL" not in res.stdout' -- 2.47.2