We need to check the exact DNS requests & response being exchanged
between sd-resolved & dnsmasq, to better understand how systemd-resolved
is validating that dnsmasq supports dnssec (even though the --dnssec
flag isn't passed by LXD to it) and why that is causing it to expect
.lxd to support DNSSEC.
The "allow-downgrade" mechanism should detect such instances and accept
them without DNSSEC validation.
** Also affects: dnsmasq (Ubuntu)
Importance: Undecided
Status: New
** Changed in: dnsmasq (Ubuntu)
Assignee: (unassigned) => Lukas Märdian (slyon)
** Changed in: dnsmasq (Ubuntu)
Status: New => Triaged
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2119652
Title:
systemd-resolved-dnssec breaks name resolution on lxd domain
To manage notifications about this bug go to:
https://bugs.launchpad.net/lxd/+bug/2119652/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs