We need to check the exact DNS requests & response being exchanged
between sd-resolved & dnsmasq, to better understand how systemd-resolved
is validating that dnsmasq supports dnssec (even though the --dnssec
flag isn't passed by LXD to it) and why that is causing it to expect
.lxd to support DNSSEC.

The "allow-downgrade" mechanism should detect such instances and accept
them without DNSSEC validation.

** Also affects: dnsmasq (Ubuntu)
   Importance: Undecided
       Status: New

** Changed in: dnsmasq (Ubuntu)
     Assignee: (unassigned) => Lukas Märdian (slyon)

** Changed in: dnsmasq (Ubuntu)
       Status: New => Triaged

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2119652

Title:
  systemd-resolved-dnssec breaks name resolution on lxd domain

To manage notifications about this bug go to:
https://bugs.launchpad.net/lxd/+bug/2119652/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to