]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
test: explicitly set nsec3-iterations to 0
authorFrantisek Sumsal <frantisek@sumsal.cz>
Tue, 30 Jan 2024 15:27:58 +0000 (16:27 +0100)
committerLuca Boccassi <luca.boccassi@gmail.com>
Tue, 30 Jan 2024 17:53:10 +0000 (17:53 +0000)
knot v3.2 and later does this by default. knot v3.1 still has the default set to
10, but it also introduced a warning that the default will be changed to 0 in
later versions, so it effectively complains about its own default, which then
fails the config check. Let's just set the value explicitly to zero to avoid
that.

~# knotc --version
knotc (Knot DNS), version 3.1.6
~# grep nsec3-iterations test/knot-data/knot.conf || echo nope
nope
~# knotc -c /build/test/knot-data/knot.conf conf-check
warning: config, policy[auto_rollover_nsec3].nsec3-iterations defaults to 10, since version 3.2 the default becomes 0
Configuration is valid

Follow-up to 0652cf8e7b.

test/knot-data/knot.conf

index 22800f6cea31b3a4eacfd82fc3824fe5de53c7bc..b8b9e7925dc25588d7aba2c90ccdc4242f922c94 100644 (file)
@@ -58,6 +58,7 @@ policy:
       ds-push: parent_zone_server
       ksk-lifetime: 365d
       ksk-submission: parent_zone_sbm
+      nsec3-iterations: 0
       nsec3: on
       propagation-delay: 1s
       signing-threads: 4