Public bug reported:

The libldns1 and/or ldnsutils package(s) need to have SHA-2 RRSIG
support to be able to understand the DNSSEC records for the root zone
(".").

Not being able to verify SHA-2 hashes is fine as long as you use DNSSEC
on some alternative DNS system that is not the de facto internet. For
the rest of us, we use the (de facto) internet, and since this does not
work for the aforementioned internet, this is a problem.

My release is Ubuntu 10.04 LTS.

The expected output is (something like):

;; Number of trusted keys: 2
;; Chasing: . SOA

DNSSEC Trust tree:
. (SOA)
|---. (DNSKEY keytag: 41248 alg: 8 flags: 256)
;; Chase successful

The actual output is:

error: Error creating socket
error: No nameservers defined in the resolver
;; Number of trusted keys: 2
;; Chasing: . SOA


DNSSEC Trust tree:
. (SOA)
|---Unknown cryptographic algorithm:
.       86400   IN      RRSIG   SOA 8 0 86400 20100722000000 20100714230000 
41248 . 
iJEabLsGHtCq8qrfSbMIjzPpBLqXa0aD5cBsIp9Sf/NF0VJQQ4nl/v+j6NR6/KClkAz2VviWE4hLDzMWcil5qzZJLvqduDedk3QV+mBKNy3OVPdNIeyxK/nYtxVBJMKbynJ8pBm0vAL3TW1+0JEfD7IG0do5t84+32hQd9MbVn0=
 ;{id = 41248}
For RRset:
.       86400   IN      SOA     a.root-servers.net. nstld.verisign-grs.com. 
2010071501 1800 900 604800 86400
With key:
.       86400   IN      DNSKEY  256 3 8 
AwEAAb1gcDhBlH/9MlgUxS0ik2dwY/JiBIpV+EhKZV7LccxNc6Qlj467QjHQ3Fgm2i2LE9w6LqPFDSng5qVq1OYFyTBt3DQppqDnAPriTwW5qIQNDNFv34yo63sAdBeU4G9tv7dzT5sPyAgmVh5HDCe+6XM2+Iel1+kUKCel8Icy19hR
 ;{id = 41248 (zsk), size = 0b}
|---. (DNSKEY keytag: 41248 alg: 8 flags: 256)
No trusted keys found in tree: first error was: Unknown cryptographic algorithm
;; Chase failed.

To reproduce, add the ICANN's DNSKEYs as the trusted keys and execute
drill:

tee trusted-key.key cat << "EOF"
. IN DNSKEY 257 3 8 AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF 
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX 
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD 
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz 
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS 
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq QxA+Uk1ihz0=
. IN DNSKEY 256 3 8 AwEAAb1gcDhBlH/9MlgUxS0ik2dwY/JiBIpV+EhKZV7LccxNc6Qlj467 
QjHQ3Fgm2i2LE9w6LqPFDSng5qVq1OYFyTBt3DQppqDnAPriTwW5qIQN 
DNFv34yo63sAdBeU4G9tv7dzT5sPyAgmVh5HDCe+6XM2+Iel1+kUKCel 8Icy19hR
EOF

drill -S -k trusted-key.key . @a.root-servers.net. soa

** Affects: ldns (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: dnssec

-- 
enable SHA-2 support for drill / ldns
https://bugs.launchpad.net/bugs/606121
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to