Home GnuPG
Diffusion GnuPG 8a98aa25bb4b

dirmngr: Validate SRV records in WKD queries.

Description

dirmngr: Validate SRV records in WKD queries.

* dirmngr/server.c (proc_wkd_get): Check the returned SRV record names
to mitigate rogue DNS servers.

I am not sure wether this really is very useful because the security
relies on a trustworthy DNS system anyway. However, that check is
easy enough to do.

(cherry picked from commit ebe727ef596eefebb5eff7d03a98649ffc7ae3ee)

  • Signed-off-by: Werner Koch <wk@gnupg.org>

Details

Provenance
wernerAuthored on Jul 27 2018, 12:23 PM
Parents
rG4f59187a17f1: common: New function to validate domain names.
Branches
Unknown
Tags
Unknown