Public bug reported:

On 18.04 with bind9/bionic-updates,bionic-proposed,now 1:9.11.3+dfsg-
1ubuntu1.9


When the zone file includes:

@       IN      CAA     "letsencrypt.org"

An error occurs when trying to sign the zone:

$ sudo dnssec-signzone -v 255 -o example.com example.com.hosts
dnssec-signzone: using 4 cpus
dnssec-signzone: error: dns_rdata_fromtext: example.com.hosts:14: not a valid 
number
dnssec-signzone: fatal: failed loading zone from 'example.com.hosts': not a 
valid number

This is unfortunate as it prevents achieving an optimum configuration
including an advisory note from SSLLabs tests.

** Affects: bind9 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1843551

Title:
  dnssec-signzone: error when CAA record exists

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/bind9/+bug/1843551/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to