From owner-freebsd-stable@FreeBSD.ORG Wed Jan 6 23:15:18 2010 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DB1BC10657A2 for ; Wed, 6 Jan 2010 23:15:18 +0000 (UTC) (envelope-from stephen@missouri.edu) Received: from cauchy.math.missouri.edu (cauchy.math.missouri.edu [128.206.184.213]) by mx1.freebsd.org (Postfix) with ESMTP id 725748FC24 for ; Wed, 6 Jan 2010 23:15:13 +0000 (UTC) Received: from laptop3.gateway.2wire.net (cauchy.math.missouri.edu [128.206.184.213]) by cauchy.math.missouri.edu (8.14.3/8.14.3) with ESMTP id o06NFCvQ067031 for ; Wed, 6 Jan 2010 17:15:12 -0600 (CST) (envelope-from stephen@missouri.edu) Message-ID: <4B451980.8010403@missouri.edu> Date: Wed, 06 Jan 2010 17:15:12 -0600 From: Stephen Montgomery-Smith User-Agent: Mozilla/5.0 (X11; U; FreeBSD amd64; en-US; rv:1.8.1.23) Gecko/20091222 Firefox/3.5.5 MIME-Version: 1.0 To: freebsd-stable@freebsd.org References: <201001062254.o06Msphj089054@freefall.freebsd.org> In-Reply-To: <201001062254.o06Msphj089054@freefall.freebsd.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: FreeBSD Security Advisory FreeBSD-SA-10:01.bind X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Jan 2010 23:15:18 -0000 FreeBSD Security Advisories wrote: > I. Background > > BIND 9 is an implementation of the Domain Name System (DNS) protocols. > The named(8) daemon is an Internet Domain Name Server. > > DNS Security Extensions (DNSSEC) provides data integrity, origin > authentication and authenticated denial of existence to resolvers. > > II. Problem Description > > If a client requests DNSSEC records with the Checking Disabled (CD) flag > set, BIND may cache the unvalidated responses. These responses may later > be returned to another client that has not set the CD flag. How do I find out if my named server is using DNSSEC? I am using the vanilla defaults with named on FreeBSD.