Merge pull request #1106 from IngmarStein/filter_aaaa_dnssec

Filter AAAA: allow modification of unsigned responses for DNSSEC-aware clients
This commit is contained in:
Shreyas Zare
2024-11-16 18:31:15 +05:30
committed by GitHub

View File

@@ -116,7 +116,16 @@ namespace FilterAaaa
return response;
if (request.DnssecOk)
return response;
{
foreach (DnsResourceRecord record in response.Answer)
{
if (record.Type == DnsResourceRecordType.RRSIG)
{
//response is signed and the client is DNSSEC aware; must not be modified
return response;
}
}
}
if (response.RCODE != DnsResponseCode.NoError)
return response;