From 23775c6006ecf68d1da6b08488dd8242173bbd4d Mon Sep 17 00:00:00 2001 From: Mark Andrews Date: Fri, 29 Nov 2024 17:20:39 +1100 Subject: [PATCH] Do not sign non DNSKEY RRset with revoked keys It does not make sense to sign RRsets other than DNSKEY with revoked keys. --- bin/dnssec/dnssec-signzone.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c index eece8554f9..bb707b85d2 100644 --- a/bin/dnssec/dnssec-signzone.c +++ b/bin/dnssec/dnssec-signzone.c @@ -673,6 +673,10 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name, for (key = ISC_LIST_HEAD(keylist); key != NULL; key = ISC_LIST_NEXT(key, link)) { + if (REVOKE(key->key) && set->type != dns_rdatatype_dnskey) { + continue; + } + if (nowsignedby[key->index]) { continue; }