summaryrefslogtreecommitdiff
path: root/src/resolve/resolved-dns-dnssec.c
AgeCommit message (Expand)AuthorFilesLines
2018-04-06tree-wide: drop license boilerplateZbigniew Jędrzejewski-Szmek1-13/+0
2018-02-05resolved: use _cleanup_ in one more placeZbigniew Jędrzejewski-Szmek1-10/+4
2018-02-05resolved: fix memleak of gcrypt context on errorZbigniew Jędrzejewski-Szmek1-28/+13
2017-12-12resolve: add support for RFC 8080 (#7600)ott1-38/+187
2017-11-19Add SPDX license identifiers to source files under the LGPLZbigniew Jędrzejewski-Szmek1-0/+1
2017-10-04Merge pull request #6974 from keszybz/clean-up-definesLennart Poettering1-2/+2
2017-10-04tree-wide: use IN_SET macro (#6977)Yu Watanabe1-2/+2
2017-10-04build-sys: use #if Y instead of #ifdef Y everywhereZbigniew Jędrzejewski-Szmek1-2/+2
2017-02-17resolved: fix NSEC proofs for missing TLDsLennart Poettering1-2/+6
2016-10-23tree-wide: drop NULL sentinel from strjoinZbigniew Jędrzejewski-Szmek1-1/+1
2016-07-11treewide: fix typos and remove accidental repetition of wordsTorstein Husebø1-1/+1
2016-04-13tree-wide: remove useless NULLs from strjoinaZbigniew Jędrzejewski-Szmek1-1/+1
2016-02-16Replace DNS_RESOURCE_KEY_NAME with a version which always returns "." for rootZbigniew Jędrzejewski-Szmek1-26/+26
2016-02-13Merge pull request #2589 from keszybz/resolve-tool-2Lennart Poettering1-16/+4
2016-02-12Typo fixesMichael Biebl1-3/+3
2016-02-11Move initialize_libgcrypt to separate fileZbigniew Jędrzejewski-Szmek1-16/+4
2016-02-10tree-wide: remove Emacs lines from all filesDaniel Mack1-2/+0
2016-02-07treewide: fix typos and spacingTorstein Husebø1-1/+1
2016-01-31resolved: allow building without libgcryptMichael Olbrich1-0/+75
2016-01-31resolved: make dnssec_nsec_test_enclosed() staticMichael Olbrich1-1/+1
2016-01-31resolved: reorder functionsMichael Olbrich1-62/+62
2016-01-26update TODOLennart Poettering1-12/+0
2016-01-25resolved: don't insist in RRSIG metadata for NSEC3 RRs that have not been aut...Lennart Poettering1-3/+4
2016-01-25update DNSSEC TODOLennart Poettering1-3/+0
2016-01-25resolved: log each time we increase the DNSSEC verdict countersLennart Poettering1-0/+8
2016-01-25resolve: use different bitmap checking rules when we find an exact NSEC3 matc...Lennart Poettering1-12/+25
2016-01-18update DNSSEC TODOLennart Poettering1-3/+0
2016-01-18resolved: rework IDNA logicLennart Poettering1-10/+0
2016-01-17resolved: update DNSSEC TODOLennart Poettering1-2/+3
2016-01-17resolved: update RFCs list and TODO listLennart Poettering1-8/+5
2016-01-17resolved: complete NSEC non-existance proofsLennart Poettering1-68/+161
2016-01-17resolved: make sure the NSEC proof-of-non-existance check also looks for wild...Lennart Poettering1-11/+64
2016-01-17resolved: on negative NODATA replies, properly deal with empty non-terminalsLennart Poettering1-5/+58
2016-01-17resolved: rename dnssec_verify_dnskey() → dnssec_verify_dnskey_by_ds()Lennart Poettering1-3/+3
2016-01-17resolved: be stricter when using NSEC3Lennart Poettering1-1/+8
2016-01-17resolved: when validating an RRset, store information about the synthesizing ...Lennart Poettering1-49/+109
2016-01-17resolved: do not use NSEC RRs from the wrong zone for proofsLennart Poettering1-0/+13
2016-01-17resolved: ignore DS RRs without generating an error if they use an unsupporte...Lennart Poettering1-2/+2
2016-01-17resolved: some RR types may appear only or not at all in a zone apexLennart Poettering1-6/+30
2016-01-13resolved: implement the full NSEC and NSEC3 postive wildcard proofsLennart Poettering1-1/+143
2016-01-13resolved: refuse validating wildcard RRs for SOA, NSEC3, DNAMELennart Poettering1-0/+5
2016-01-13resolved: properly handles RRs in domains beginning in an asterisk labelLennart Poettering1-1/+12
2016-01-13resolved: optimize dnssec_verify_rrset() a bitLennart Poettering1-12/+16
2016-01-13resolved: allocate bounded strings on stack instead of heap, if we canLennart Poettering1-6/+3
2016-01-13resolved: consider inverted RRSIG validity intervals expiredLennart Poettering1-1/+2
2016-01-11resolved: properly look for NSEC/NSEC3 RRs when getting a positive wildcard r...Lennart Poettering1-5/+103
2016-01-11resolved: split up nsec3_hashed_domain() into two callsLennart Poettering1-25/+30
2016-01-11resolved: drop flags unused parameter from nsec3_is_goodLennart Poettering1-4/+4
2016-01-11basic: introduce generic ascii_strlower_n() call and make use of it everywhereLennart Poettering1-7/+1
2016-01-11resolved: use dns_answer_size() where appropriate to handle NULL DnsAnswerLennart Poettering1-1/+1