Re: Re: La racine est signée et la cl é distribuée

Alain Thivillon <[email protected]>
Newsgroups gmane.network.dns.french
Message-ID <[email protected]>
Le 16 juillet 2010 11:08, Stephane Bortzmeyer <[email protected]> a écrit :
> On Thu, Jul 15, 2010 at 11:31:35PM +0200,
>  Stephane Bortzmeyer <[email protected]> wrote
>  a message of 28 lines which said:
>
>> RAS de particulier
>
> Et pour ceux qui veulent valider, ils doivent récupérer la clé de
> manière sûre. Une des façons :

Ils devront aussi avoir les dernières versions de logiciel, car
l'algorithme utilisé RSA-SHA256 n'a été défini pour DNSSEC que dans le
RFC5702, et ca date d'octobre dernier ...

Exemple : Unbuntu 8 et 9 n'ont ni un Bind, ni un Unbound à jour pour
cela, et pas de backport. Je n'ose pas demander pour les Debian
stables.

Bind: config: error: /etc/bind/named.conf.options:46: configuring
trusted key for '.':  algorithm is unsupported
Unbound: warning: trust anchor . has no supported algorithms, the
anchor is ignored (check if you need to upgrade unbound and openssl)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.