Files
Wez Furlong 3e549a9fcb dns: derive DNSSEC status for hickory negative answers
The hickory backend hardcoded the secure and bogus flags to false for
NODATA/NXDOMAIN responses, discarding the DNSSEC proof that hickory does
deliver. A securely denied answer carries validated authority records
(SOA/NSEC/RRSIG) proving the absence; derive secure and bogus from those
the same way we already do for the answer section of a positive response.

This closes a divergence from the unbound backend: a securely proven "no
MX" (common for signed domains that publish no MX) now marks the implicit
MX secure so DANE can engage, and a tampered denial can surface as bogus
and defer rather than silently reporting not-applicable.
2026-07-06 16:19:16 +01:00
..
2026-02-04 09:10:25 +00:00
2026-05-06 13:29:15 +00:00
2024-12-07 09:17:54 -07:00
2025-04-09 10:26:07 -07:00
2026-06-23 15:47:08 +01:00
2026-03-02 15:42:27 +00:00
2026-06-23 15:47:08 +01:00
2026-06-23 09:24:25 +01:00
2025-04-09 10:26:07 -07:00
2026-05-12 16:50:01 +01:00
2025-10-08 11:00:37 +01:00
2026-02-24 11:03:43 +00:00
2025-04-09 10:26:12 -07:00
2026-06-23 09:59:34 +01:00
2025-04-09 10:26:07 -07:00
2024-12-07 09:17:54 -07:00
2026-06-23 15:47:08 +01:00
2026-06-23 15:47:08 +01:00
2025-04-09 10:26:07 -07:00
2026-07-06 11:46:49 +01:00
2026-06-23 09:24:25 +01:00
2024-11-13 13:50:27 -07:00
2026-06-23 09:59:34 +01:00
2025-04-09 10:26:07 -07:00
2025-04-09 10:26:07 -07:00