mirror of
https://github.com/fergalmoran/DnsServer.git
synced 2026-03-12 00:19:18 +00:00
AuthZoneManager: updated LoadTrustAnchorsTo() to skip revoked dns keys.
This commit is contained in:
@@ -1897,7 +1897,7 @@ namespace DnsServerCore.Dns.ZoneManagers
|
||||
{
|
||||
DnsDNSKEYRecord dnsKey = dnsKeyRecord.RDATA as DnsDNSKEYRecord;
|
||||
|
||||
if (dnsKey.Flags.HasFlag(DnsDnsKeyFlag.SecureEntryPoint))
|
||||
if (dnsKey.Flags.HasFlag(DnsDnsKeyFlag.SecureEntryPoint) && !dnsKey.Flags.HasFlag(DnsDnsKeyFlag.Revoke))
|
||||
{
|
||||
DnsDSRecord dsRecord = dnsKey.CreateDS(dnsKeyRecord.Name, DnssecDigestType.SHA256);
|
||||
dnsClient.AddTrustAnchor(zoneInfo.Name, dsRecord);
|
||||
|
||||
Reference in New Issue
Block a user