[GH-ISSUE #214] DNSKEY query not returning RRSIG (or DNSKEY not being signed) #101

Closed
opened 2026-03-07 22:18:52 +03:00 by kerem · 1 comment
Owner

Originally created by @bluejekyll on GitHub (Sep 27, 2017).
Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/214

see #209 and #213

Originally created by @bluejekyll on GitHub (Sep 27, 2017). Original GitHub issue: https://github.com/hickory-dns/hickory-dns/issues/214 see #209 and #213
kerem 2026-03-07 22:18:52 +03:00
Author
Owner

@bluejekyll commented on GitHub (Sep 28, 2017):

@TerraX-net, I remember now why this is happening. When building the signing and validation logic for DNSSec, I looked at this self-signed DNSKEY, and it didn't make sense to me to sign. This is because DNSKEY's are validated against DS records, making an RRSIG for the zone's DNSKEY irrelevant to the proof chain. I should be able to self-sign the DNSKEY without much issue.

This should be an easy fix. In #215 I plan to add tests for validating all the issues you've raised so far.

<!-- gh-comment-id:332742179 --> @bluejekyll commented on GitHub (Sep 28, 2017): @TerraX-net, I remember now why this is happening. When building the signing and validation logic for DNSSec, I looked at this self-signed DNSKEY, and it didn't make sense to me to sign. This is because DNSKEY's are validated against DS records, making an RRSIG for the zone's DNSKEY irrelevant to the proof chain. I should be able to self-sign the DNSKEY without much issue. This should be an easy fix. In #215 I plan to add tests for validating all the issues you've raised so far.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/hickory-dns#101
No description provided.