BIND 10 #955: xfrin should check TSIG before other part of incoming message
BIND 10 Development
do-not-reply at isc.org
Fri May 20 22:56:25 UTC 2011
#955: xfrin should check TSIG before other part of incoming message
-------------------------------+-----------------------------------------
Reporter: jinmei | Owner:
Type: defect | Status: new
Priority: major | Milestone: New Tasks
Component: xfrin | Keywords:
Sensitive: 0 | Defect Severity: N/A
Sub-Project: DNS | Feature Depending on Ticket:
Estimated Difficulty: 0 | Add Hours to Ticket: 0
Total Hours: 0 | Internal?: 0
-------------------------------+-----------------------------------------
The current implementation of xfrin checks some DNS message values
before checking TSIG. This should be reversed. (not a big deal,
though, because bogus responses would be discarded either way and it's
in the context of receiving responses so no compliance issue on how to
respond to them exists).
--
Ticket URL: <http://bind10.isc.org/ticket/955>
BIND 10 Development <http://bind10.isc.org>
BIND 10 Development
More information about the bind10-tickets
mailing list