Report information
The Basics
Id:
37541
Status:
resolved
Priority:
Medium/Medium
Queue:

People
Owner:
Nobody in particular
Requestors:
Cc:
AdminCc:

BugTracker
Version Fixed:
9.9.7, 9.9.7-S1, 9.10.2, 9.11.0
Version Found:
(no value)
Versions Affected:
(no value)
Versions Planned:
(no value)
Priority:
(no value)
Severity:
S2 Normal
CVSS Score:
(no value)
CVE ID:
(no value)
Component:
BIND Server
Area:
test

Dates
Created:Mon, 20 Oct 2014 17:56:21 -0400
Updated:Thu, 03 Aug 2017 22:13:49 -0400
Closed:Wed, 29 Oct 2014 20:29:39 -0400



This bug tracker is no longer active.

Please go to our Gitlab to submit issues (both feature requests and bug reports) for active projects maintained by Internet Systems Consortium (ISC).

Due to security and confidentiality requirements, full access is limited to the primary maintainers.

Subject: Behavior of the BIND validating resolver when an unknown crypto algorithm is specified.
Hello, Geoff --

This is Michael McNally from ISC -- we met at DNS-OARC and briefly
discussed a behavior you reported observing in BIND that was not acting
as expected.  I told you when I returned from travel after the conference
that I would look into it and make sure the matter gets referred to the
developers for action, so I am beginning by creating this ticket in our
bug-tracking system to follow the issue.

Excuse me while I first restate the issue to make sure I understand your report:

As I understand it, while experimenting with BIND validation, you tested a
case where BIND was asked to validate DNSSEC records signed with an
unimplemented (actually bogus) cryptographic algorithm.

In violation of expectation, you received an error response, whereas what
BIND should be returning (by design) is an answer without validation flags set.
Is that a fair summary?

Michael McNally
ISC Support