mirror of
https://gitlab.isc.org/isc-projects/bind9
synced 2025-09-02 23:55:27 +00:00
Don't delete the NSEC3PARAM immediately
Wait until the new NSEC or NSEC3 chain is generated then it should be deleted.
This commit is contained in:
@@ -1133,12 +1133,6 @@ dns_nsec3param_deletechains(dns_db_t *db, dns_dbversion_t *ver,
|
|||||||
dns_rdata_t private = DNS_RDATA_INIT;
|
dns_rdata_t private = DNS_RDATA_INIT;
|
||||||
|
|
||||||
dns_rdataset_current(&rdataset, &rdata);
|
dns_rdataset_current(&rdataset, &rdata);
|
||||||
|
|
||||||
CHECK(dns_difftuple_create(diff->mctx, DNS_DIFFOP_DEL, origin,
|
|
||||||
rdataset.ttl, &rdata, &tuple));
|
|
||||||
CHECK(do_one_tuple(&tuple, db, ver, diff));
|
|
||||||
INSIST(tuple == NULL);
|
|
||||||
|
|
||||||
dns_nsec3param_toprivate(&rdata, &private, privatetype, buf,
|
dns_nsec3param_toprivate(&rdata, &private, privatetype, buf,
|
||||||
sizeof(buf));
|
sizeof(buf));
|
||||||
buf[2] = DNS_NSEC3FLAG_REMOVE;
|
buf[2] = DNS_NSEC3FLAG_REMOVE;
|
||||||
|
Reference in New Issue
Block a user