> * If BIND, acting as a DNSSEC validating server, has two or more
> trust anchors configured in named.conf for the same zone (such as
> example.com) and the response for a record in that zone from the
> authoritative server includes a bad signature, the validating
> server will crash while trying to validate that query.
Does this change need backporting to 9.6-ESV? Is an isolated patch
available?
It's this one which is also in 9.6-ESV-R2:
2869. [bug] Fix arguments to dns_keytable_findnextkeynode() call.
RT #20877]
Regards,
Cathy
> _______________________________________________
> bind-users mailing list
> bind-...@lists.isc.org
> https://lists.isc.org/mailman/listinfo/bind-users