mirror of
https://gitlab.isc.org/isc-projects/bind9
synced 2025-09-04 16:45:24 +00:00
Add todo in dnssec system test for [GL #1689]
Add a note why we don't have a test case for the issue. It is tricky to write a good test case for this if our tools are not allowed to create signatures for unsupported algorithms.
This commit is contained in:
@@ -3562,6 +3562,13 @@ n=$((n+1))
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
status=$((status+ret))
|
||||
|
||||
# TODO: test case for GL #1689.
|
||||
# If we allow the dnssec tools to use deprecated algorithms (such as RSAMD5)
|
||||
# we could write a test that signs a zone with supported and unsupported
|
||||
# algorithm, apply a fixed rrset order such that the unsupported algorithm
|
||||
# precedes the supported one in the DNSKEY RRset, and verify the result still
|
||||
# validates succesfully.
|
||||
|
||||
echo_i "check that a lone non matching CDNSKEY record is rejected ($n)"
|
||||
ret=0
|
||||
(
|
||||
|
Reference in New Issue
Block a user