dnsmasq: add fix related to DNSSEC verification from upstream
authorUwe Kleine-König <uwe+openwrt@kleine-koenig.org>
Mon, 27 Jan 2025 15:12:23 +0000 (16:12 +0100)
committerHauke Mehrtens <hauke@hauke-m.de>
Mon, 27 Jan 2025 22:53:29 +0000 (23:53 +0100)
commitdaef29c75d284a31ca5d957e64b3bf4629e7d049
tree376ed9f2c51d2dc0696b9f18739fb2b328d6fbfc
parent50cb934142e3f6668dc8ebb8a7e54e6b17e14bd1
dnsmasq: add fix related to DNSSEC verification from upstream

To find the DS record for a given zone the parent zone's nameserver must
be queried and not the nameserver for the zone. Otherwise DNSSEC
verification for unsigned delegations breaks.

Signed-off-by: Uwe Kleine-König <uwe+openwrt@kleine-koenig.org>
Link: https://patchwork.ozlabs.org/project/openwrt/patch/20250127151223.1420006-1-uwe+openwrt@kleine-koenig.org/
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
(cherry picked from commit 6dc0f0c50cf1072ec3751c0fb1fc152a0a86487d)
package/network/services/dnsmasq/Makefile
package/network/services/dnsmasq/patches/0003-Handle-DS-queries-to-auth-zones.patch [new file with mode: 0644]