package/systemd: enabled dnssec when available
authorJames Hilliard <james.hilliard1@gmail.com>
Sun, 8 Mar 2020 22:03:16 +0000 (16:03 -0600)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 12 Apr 2020 13:47:09 +0000 (15:47 +0200)
When libgcrypt is available set default-dnssec to the backwards
compatible allow-downgrade option.

Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/systemd/systemd.mk

index 623e9422053c1afe331869d888485ac6bed279a9..009f599c104bc45c84c8db6fae894046cd90c8d5 100644 (file)
@@ -26,7 +26,6 @@ SYSTEMD_CONF_OPTS += \
        -Dman=false \
        -Dima=false \
        -Dldconfig=false \
-       -Ddefault-dnssec=no \
        -Ddefault-hierarchy=hybrid \
        -Dtests=false \
        -Dsplit-bin=true \
@@ -154,9 +153,9 @@ endif
 
 ifeq ($(BR2_PACKAGE_LIBGCRYPT),y)
 SYSTEMD_DEPENDENCIES += libgcrypt
-SYSTEMD_CONF_OPTS += -Dgcrypt=true
+SYSTEMD_CONF_OPTS += -Ddefault-dnssec=allow-downgrade -Dgcrypt=true
 else
-SYSTEMD_CONF_OPTS += -Dgcrypt=false
+SYSTEMD_CONF_OPTS += -Ddefault-dnssec=no -Dgcrypt=false
 endif
 
 ifeq ($(BR2_PACKAGE_PCRE2),y)