On Thu 2017-10-19 23:23:08 +0200, Sergio Gelato wrote: > * Daniel Kahn Gillmor [2017-10-19 15:44:40 -0400]: >> However, i'm not convinced that dnssec-dsfromkey is at fault, because i >> think the versions of dnssec-dsfromkey in stretch and buster both have >> the same behavior. > > It turns out the following change from version 2017020200 of the package > was not included in the jessie backport: > > * Rewrite DS creation check to xml2 and ldnsutils, as neither xmllint > nor bind9utils handle multiple DNSKEY in one file correctly
Thanks for the pointer. This isn't the only problem, though, as the build verification still isn't working out quite right. after a bit of investigation, it looks like we're also missing a few other commits, which i'll try to cherry-pick and build later tonight. --dkg
signature.asc
Description: PGP signature