diff options
author | Werner Koch <[email protected]> | 2018-07-27 10:23:38 +0000 |
---|---|---|
committer | Werner Koch <[email protected]> | 2018-07-27 10:24:23 +0000 |
commit | ebe727ef596eefebb5eff7d03a98649ffc7ae3ee (patch) | |
tree | 6d3c7666fa084d11705a40aa872cc31bbbb9bcb6 /g10/call-dirmngr.c | |
parent | common: New function to validate domain names. (diff) | |
download | gnupg-ebe727ef596eefebb5eff7d03a98649ffc7ae3ee.tar.gz gnupg-ebe727ef596eefebb5eff7d03a98649ffc7ae3ee.zip |
dirmngr: Validate SRV records in WKD queries.
* dirmngr/server.c (proc_wkd_get): Check the returned SRV record names
to mitigate rogue DNS servers.
--
I am not sure wether this really is very useful because the security
relies on a trustworthy DNS system anyway. However, that check is
easy enough to do.
Signed-off-by: Werner Koch <[email protected]>
Diffstat (limited to 'g10/call-dirmngr.c')
0 files changed, 0 insertions, 0 deletions