package/{chrony, ntp, openntpd}: turn off DNSSEC validation
authorJames Hilliard <james.hilliard1@gmail.com>
Thu, 8 Jul 2021 11:16:27 +0000 (05:16 -0600)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Fri, 16 Jul 2021 20:58:08 +0000 (22:58 +0200)
commitc2db53caca63ea8fca17823e37d496774aefd477
treea143f338ffdef2a394ad0dcf549ae92936836731
parent2519b17d849eb9afb6669b8c5b39de47894b1716
package/{chrony, ntp, openntpd}: turn off DNSSEC validation

We have a chicken and egg problem: validation of DNSSEC signatures
doesn't work without a correct clock, but to set the correct clock we
need to contact NTP servers which requires resolving a hostname, which
would normally require DNSSEC validation.

Let's break the cycle by excluding NTP hostname resolution from
validation for now.

Details:
https://github.com/systemd/systemd/commit/abf4e5c1d3ad767bc0ed67883e8e4d916af095ec

Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/chrony/chrony.service
package/ntp/ntpd.service
package/openntpd/ntpd.service