Files
bind9/bin/tests/system/checkconf/kasp-bad-nsec3-alg.conf
Matthijs Mekking 00c5dabea3 Add check for NSEC3 and key algorithms
NSEC3 is not backwards compatible with key algorithms that existed
before the RFC 5155 specification was published.
2020-11-26 10:43:59 +01:00

25 lines
576 B
Plaintext

/*
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
*
* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
*
* See the COPYRIGHT file distributed with this work for additional
* information regarding copyright ownership.
*/
dnssec-policy "bad-salt" {
keys {
csk lifetime unlimited algorithm rsasha1;
};
nsec3param ;
};
zone "example.net" {
type master;
file "example.db";
dnssec-policy "bad-salt";
};