diff options
| author | Werner Koch <[email protected]> | 2018-07-27 10:23:38 +0000 |
|---|---|---|
| committer | Werner Koch <[email protected]> | 2018-07-27 10:24:23 +0000 |
| commit | ebe727ef596eefebb5eff7d03a98649ffc7ae3ee (patch) | |
| tree | 6d3c7666fa084d11705a40aa872cc31bbbb9bcb6 /g10/mainproc.c | |
| parent | common: New function to validate domain names. (diff) | |
| download | gnupg-ebe727ef596eefebb5eff7d03a98649ffc7ae3ee.tar.gz gnupg-ebe727ef596eefebb5eff7d03a98649ffc7ae3ee.zip | |
dirmngr: Validate SRV records in WKD queries.
* dirmngr/server.c (proc_wkd_get): Check the returned SRV record names
to mitigate rogue DNS servers.
--
I am not sure wether this really is very useful because the security
relies on a trustworthy DNS system anyway. However, that check is
easy enough to do.
Signed-off-by: Werner Koch <[email protected]>
Diffstat (limited to 'g10/mainproc.c')
0 files changed, 0 insertions, 0 deletions
