Re: [Dnsmasq-discuss] Remove DSA-NSEC3-SHA1 & DSA DNSSEC algorithm as this is set to status MUST NOT implement in RFC 8624

2020-02-27 Thread Simon Kelley
Looks sensible, I've pushed the equivalent, and removed the now-redundant DSA signature verification code too. Simon. On 24/02/2020 07:08, Loganaden Velvindron wrote: > Google might mangle the patch. Feedback welcomed. > > RFC 8624 Section 3.1 (https://www.rfc-editor.org/rfc/rfc8624.txt )says

Re: [Dnsmasq-discuss] Remove DSA-NSEC3-SHA1 & DSA DNSSEC algorithm as this is set to status MUST NOT implement in RFC 8624

2020-02-25 Thread Vladislav Grishenko
Hi, Have that since last year with possibility to reenable with HAVE_DNS build-time define: https://github.com/themiron/dnsmasq/commit/5a1a8bc039561455677e825194f470219093aaf6.patch Also, GOST is obsolete and GOST2012 is not standardized yet. This helps to turn it off by default: https://github