From: Tomas Krizek Date: Mon, 2 Nov 2020 10:17:59 +0000 (+0100) Subject: distro/tests: update DNSSEC bogus test X-Git-Tag: v5.2.0~3^2 X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=refs%2Fenvironments%2Fobs-knot-resolver-bs4hbr%2Fdeployments%2F1218;p=thirdparty%2Fknot-resolver.git distro/tests: update DNSSEC bogus test dnssec-failed.org domain uses RSA/SHA1 algorithm, which is considered insecure by Fedora 33+ policy. --- diff --git a/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml b/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml index 990d4ca94..52bbbb2f8 100644 --- a/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml +++ b/distro/tests/ansible-roles/knot_resolver/tasks/test_dnssec.yaml @@ -1,15 +1,15 @@ --- # SPDX-License-Identifier: GPL-3.0-or-later -- name: dnssec_test dnssec-failed.org +cd returns NOERROR +- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. +cd returns NOERROR tags: - test - shell: kdig +cd @127.0.0.1 dnssec-failed.org + shell: kdig +cd @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl. register: res failed_when: '"status: NOERROR" not in res.stdout' -- name: dnssec_test dnssec-failed.org returns SERVFAIL +- name: dnssec_test bogussig.bad-dnssec.wb.sidnlabs.nl. returns SERVFAIL tags: - test - shell: kdig @127.0.0.1 dnssec-failed.org + shell: kdig @127.0.0.1 bogussig.bad-dnssec.wb.sidnlabs.nl. register: res failed_when: '"status: SERVFAIL" not in res.stdout'