Conversation

so apparently bind had a bug with the dnssec-validate option where if you set it to yes without overriding the trust anchors it would do………nothing

they “fixed” it by breaking prod instead of just making it use the correct trust anchors

1
0
0

old internet software is programmed in a way where they remove every bit of UX until all that remains is pain

Why yes i would definitely expect enabling dnssec validation……makes the server not work. not use the default trust anchors. which it ships. and uses. if you enable “automatic” dnssec validation

1
2
3

i presume this may be why debian et al are so popular.

sure you may not get recent versions

but at the very least dave named will not explode your servers because fixing their bug might actually improve their program

1
0
0

i am surprised these posts even federate given that the server doesn’t have working dns, and the authorative dns servers for chir.rs are down due to this garbage

1
0
2