dnsmasq: add fix related to DNSSEC verification from upstream
authorUwe Kleine-König <uwe+openwrt@kleine-koenig.org>
Mon, 27 Jan 2025 15:12:23 +0000 (16:12 +0100)
committerHauke Mehrtens <hauke@hauke-m.de>
Mon, 27 Jan 2025 22:38:02 +0000 (23:38 +0100)
commit6dc0f0c50cf1072ec3751c0fb1fc152a0a86487d
treeb397fb0eea8bae3df365fd670b9ff7738636c2a0
parentdab52c00d712a421d6e61eebc51359e5d38ad347
dnsmasq: add fix related to DNSSEC verification from upstream

To find the DS record for a given zone the parent zone's nameserver must
be queried and not the nameserver for the zone. Otherwise DNSSEC
verification for unsigned delegations breaks.

Signed-off-by: Uwe Kleine-König <uwe+openwrt@kleine-koenig.org>
Link: https://patchwork.ozlabs.org/project/openwrt/patch/20250127151223.1420006-1-uwe+openwrt@kleine-koenig.org/
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
package/network/services/dnsmasq/Makefile
package/network/services/dnsmasq/patches/0003-Handle-DS-queries-to-auth-zones.patch [new file with mode: 0644]