On Thu 2017-10-19 23:23:08 +0200, Sergio Gelato wrote:
> * Daniel Kahn Gillmor [2017-10-19 15:44:40 -0400]:
>> However, i'm not convinced that dnssec-dsfromkey is at fault, because i
>> think the versions of dnssec-dsfromkey in stretch and buster both have
>> the same behavior.
>
> It turns out the following change from version 2017020200 of the package
> was not included in the jessie backport:
>
>   * Rewrite DS creation check to xml2 and ldnsutils, as neither xmllint
>     nor bind9utils handle multiple DNSKEY in one file correctly

Thanks for the pointer.  This isn't the only problem, though, as the
build verification still isn't working out quite right.

after a bit of investigation, it looks like we're also missing a few
other commits, which i'll try to cherry-pick and build later tonight.

   --dkg

Attachment: signature.asc
Description: PGP signature

Reply via email to